MGASA-2021-0573

Source
https://advisories.mageia.org/MGASA-2021-0573.html
Import Source
https://advisories.mageia.org/MGASA-2021-0573.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0573
Related
Published
2021-12-21T23:27:37Z
Modified
2021-12-21T22:48:15Z
Summary
Updated x11-server packages fix security vulnerabilities
Details

Updated x11-server packages fix security vulnerabilities:

The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4008).

The handler for the CreatePointerBarrier request of the XFixes extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4009).

The handler for the Suspend request of the Screen Saver extension does not properly validate the request length leading to out of bounds memory write (CVE-2021-4010).

The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write (CVE-2021-4011).

All of these issues can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.

References
Credits

Affected packages

Mageia:8 / x11-server

Package

Name
x11-server
Purl
pkg:rpm/mageia/x11-server?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.20.14-1.mga8

Ecosystem specific

{
    "section": "core"
}