Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2020-0335 Critical Update for x11-server Memory Leak

mageia
Calendar Grey August 18, 2020
Dist Mageia Esm H88
A security notice for Mageia 2020-0335 concerning a memory initialization vulnerability in x11-server. Stay informed about potential threats and the latest patches.
Allocation for pixmap data in AllocatePixmap() does not initialize the memory in xserver, it leads to leak uninitialize heap memory to clients

Summary

Allocation for pixmap data in AllocatePixmap() does not initialize the memory in xserver, it leads to leak uninitialize heap memory to clients. When the X server runs with elevated privileges. This flaw can lead to ASLR bypass, which when combined with other flaws (known/unknown) could lead to lead to privilege elevation in the client (CVE-2020-14347).

References

- https://bugs.mageia.org/show_bug.cgi?id=27031

- https://lists.x.org/archives/xorg-announce/2020-July/003051.html

- https://www.cve.org/CVERecord?id=CVE-2020-14347

Resolution

SRPMS

- 7/core/x11-server-1.20.8-1.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 18 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0335.html
Type: security
CVE: CVE-2020-14347

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here