MGASA-2020-0335 - Updated x11-server packages fix security vulnerability

Publication date: 18 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0335.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-14347

Allocation for pixmap data in AllocatePixmap() does not initialize the memory
in xserver, it leads to leak uninitialize heap memory to clients. When the X
server runs with elevated privileges. This flaw can lead to ASLR bypass, which
when combined with other flaws (known/unknown) could lead to lead to privilege
elevation in the client (CVE-2020-14347).

References:
- https://bugs.mageia.org/show_bug.cgi?id=27031
- https://lists.x.org/archives/xorg-announce/2020-July/003051.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14347

SRPMS:
- 7/core/x11-server-1.20.8-1.1.mga7

Mageia 2020-0335: x11-server security update

Allocation for pixmap data in AllocatePixmap() does not initialize the memory in xserver, it leads to leak uninitialize heap memory to clients

Summary

Allocation for pixmap data in AllocatePixmap() does not initialize the memory in xserver, it leads to leak uninitialize heap memory to clients. When the X server runs with elevated privileges. This flaw can lead to ASLR bypass, which when combined with other flaws (known/unknown) could lead to lead to privilege elevation in the client (CVE-2020-14347).

References

- https://bugs.mageia.org/show_bug.cgi?id=27031

- https://lists.x.org/archives/xorg-announce/2020-July/003051.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14347

Resolution

MGASA-2020-0335 - Updated x11-server packages fix security vulnerability

SRPMS

- 7/core/x11-server-1.20.8-1.1.mga7

Severity
Publication date: 18 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0335.html
Type: security
CVE: CVE-2020-14347

Related News