MGASA-2020-0350 - Updated x11-server packages fix security vulnerabilities

Publication date: 27 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0350.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-14345,
     CVE-2020-14346,
     CVE-2020-14361,
     CVE-2020-14362

The handler for the XkbSetNames request does not validate the request length
before accessing its contents (CVE-2020-14345).

An integer underflow exists in the handler for the XIChangeHierarchy request
(CVE-2020-14346).

An integer underflow exist in the handler for the XkbSelectEvents request
(CVE-2020-14361).

An integer underflow exist in the handler for the CreateRegister request of
the X record extension (CVE-2020-14362).

The x11-server package has been updated to version 1.20.9, fixing these issues
and other bugs.

References:
- https://bugs.mageia.org/show_bug.cgi?id=27206
- https://lists.x.org/archives/xorg-announce/2020-August/003059.html
- https://lists.x.org/archives/xorg-announce/2020-August/003058.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14345
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14346
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14361
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14362

SRPMS:
- 7/core/x11-server-1.20.9-1.mga7

Mageia 2020-0350: x11-server security update

The handler for the XkbSetNames request does not validate the request length before accessing its contents (CVE-2020-14345)

Summary

The handler for the XkbSetNames request does not validate the request length before accessing its contents (CVE-2020-14345).
An integer underflow exists in the handler for the XIChangeHierarchy request (CVE-2020-14346).
An integer underflow exist in the handler for the XkbSelectEvents request (CVE-2020-14361).
An integer underflow exist in the handler for the CreateRegister request of the X record extension (CVE-2020-14362).
The x11-server package has been updated to version 1.20.9, fixing these issues and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=27206

- https://lists.x.org/archives/xorg-announce/2020-August/003059.html

- https://lists.x.org/archives/xorg-announce/2020-August/003058.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14345

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14346

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14361

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14362

Resolution

MGASA-2020-0350 - Updated x11-server packages fix security vulnerabilities

SRPMS

- 7/core/x11-server-1.20.9-1.mga7

Severity
Publication date: 27 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0350.html
Type: security
CVE: CVE-2020-14345, CVE-2020-14346, CVE-2020-14361, CVE-2020-14362

Related News