Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7 & 8: MGASA-2021-0219 Critical: Libx11 Input Flaw

mageia
Calendar Grey May 22, 2021
Dist Mageia Esm H88
Ubuntu security notice for libx11 highlights severe vulnerabilities in XLoadQueryFont() function impacting versions 20.04 and 21.10.
XLookupColor() and other X libraries function lack proper validation of the length of their string parameters

Summary

XLookupColor() and other X libraries function lack proper validation of the length of their string parameters. If those parameters can be controlled by an external application (for instance a color name that can be emitted via a terminal control sequence) it can lead to the emission of extra X protocol requests to the X server (CVE-2021-31535).

References

- https://bugs.mageia.org/show_bug.cgi?id=28940

- https://lists.x.org/archives/xorg-announce/2021-May/003088.html

- https://lists.x.org/archives/xorg-announce/2021-May/003089.html

- https://www.openwall.com/lists/oss-security/2021/05/18/3

- https://www.cve.org/CVERecord?id=CVE-2021-31535

Resolution

SRPMS

- 8/core/libx11-1.7.0-1.1.mga8

- 7/core/libx11-1.6.12-1.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 23 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0219.html
Type: security
CVE: CVE-2021-31535

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here