Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

Mageia: 2020-0350 Critical: x11-server Integer Underflows Advisory

mageia
Calendar Grey August 27, 2020
Dist Mageia Esm H88
Mageia has released updates for x11-server packages addressing critical security vulnerabilities, such as integer underflows. For further information and corrective measures, click here.
The handler for the XkbSetNames request does not validate the request length before accessing its contents (CVE-2020-14345)

Summary

The handler for the XkbSetNames request does not validate the request length before accessing its contents (CVE-2020-14345).
An integer underflow exists in the handler for the XIChangeHierarchy request (CVE-2020-14346).
An integer underflow exist in the handler for the XkbSelectEvents request (CVE-2020-14361).
An integer underflow exist in the handler for the CreateRegister request of the X record extension (CVE-2020-14362).
The x11-server package has been updated to version 1.20.9, fixing these issues and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=27206

- https://lists.x.org/archives/xorg-announce/2020-August/003059.html

- https://lists.x.org/archives/xorg-announce/2020-August/003058.html

- https://www.cve.org/CVERecord?id=CVE-2020-14345

- https://www.cve.org/CVERecord?id=CVE-2020-14346

- https://www.cve.org/CVERecord?id=CVE-2020-14361

- https://www.cve.org/CVERecord?id=CVE-2020-14362

Resolution

SRPMS

- 7/core/x11-server-1.20.9-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 27 Aug 2020
URL: https://advisories.mageia.org/MGASA-2020-0350.html
Type: security
CVE: CVE-2020-14345, CVE-2020-14346, CVE-2020-14361, CVE-2020-14362

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here