Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 32: FEDORA-2020-eba554b9d5 Critical: libX11 Heap Overflow

fedora
Calendar Grey August 27, 2020
Dist Fedora Esm H88
Critical Fedora update addresses heap overflow and integer overflow vulnerabilities in libX11 and their resolution.
libX11 1.6.12 (CVE-2020-14363, CVE 2020-14344)

Summary

Core X11 protocol client library.

libX11 1.6.12 (CVE-2020-14363, CVE 2020-14344)

* Wed Aug 26 2020 Peter Hutterer 1.6.12-1

- libX11 1.6.12 (CVE-2020-14363, CVE 2020-14344)

* Fri Jul 31 2020 Adam Jackson - 1.6.9-5

- Fix server reply validation issue in XIM (CVE 2020-14344)

* Tue Jul 28 2020 Fedora Release Engineering - 1.6.9-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild

[ 1 ] Bug #1862255 - CVE-2020-14344 libX11: Heap overflow in the X input method client

https://bugzilla.redhat.com/show_bug.cgi?id=1862255

[ 2 ] Bug #1872473 - CVE-2020-14363 libX11: integer overflow leads to double free in locale handling

https://bugzilla.redhat.com/show_bug.cgi?id=1872473

su -c 'dnf upgrade --advisory FEDORA-2020-eba554b9d5' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 1.6.12
Release: 1.fc32
Summary: Core X11 protocol client library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here