Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9: MGASA-2024-0121 Critical X11-Server Attack Risks

mageia
Calendar Grey April 11, 2024
Dist Mageia Esm H88
Mageia Security Update MGASA-2024-0122 addresses vulnerabilities in openjpeg and gimp to rectify severe security issues.
Heap buffer overread/data leakage in ProcXIGetSelectedEvents

Summary

Heap buffer overread/data leakage in ProcXIGetSelectedEvents. (CVE-2024-31080) Heap buffer overread/data leakage in ProcXIPassiveGrabDevice. (CVE-2024-31081) User-after-free in ProcRenderAddGlyphs. (CVE-2024-31083)

References

- https://bugs.mageia.org/show_bug.cgi?id=33058

- https://www.cve.org/CVERecord?id=CVE-2024-31080

- https://www.cve.org/CVERecord?id=CVE-2024-31081

- https://www.cve.org/CVERecord?id=CVE-2024-31083

Resolution

SRPMS

- 9/core/x11-server-21.1.8-7.4.mga9

- 9/core/x11-server-xwayland-22.1.9-1.4.mga9

- 9/core/tigervnc-1.13.1-2.4.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 11 Apr 2024
URL: https://advisories.mageia.org/MGASA-2024-0121.html
Type: security
CVE: CVE-2024-31080, CVE-2024-31081, CVE-2024-31083

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here