Advisories ยป MGASA-2020-0456

Updated x11-server packages fix security vulnerabilities

Publication date: 17 Dec 2020
Modification date: 17 Dec 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-14360 , CVE-2020-25712

Description

A flaw was found in the X.Org Server. An out-of-bounds access in the XkbSetMap
function may lead to a privilege escalation vulnerability. The highest threat
from this vulnerability is to data confidentiality and integrity as well as
system availability (CVE-2020-14360).

A flaw was found in xorg-x11-server. A heap-buffer overflow in XkbSetDeviceInfo
may lead to a privilege escalation vulnerability. The highest threat from this
vulnerability is to data confidentiality and integrity as well as system
availability (CVE-2020-25712).

The x11-server package has been updated to version 1.20.10, fixing these issues
and other bugs.
                

References

SRPMS

7/core