Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE: 2015:0045-1 Important: xorg-x11-server Denial of Service

suse
Calendar Grey January 14, 2015
Dist Suse Esm H88
Red Hat issues critical patch for kernel addressing several security flaws in Fedora.
An update that fixes 12 vulnerabilities is now available

Summary

The XOrg X11 server was updated to fix 12 security issues: * Denial of service due to unchecked malloc in client authentication (CVE-2014-8091). * Integer overflows calculating memory needs for requests (CVE-2014-8092). * Integer overflows calculating memory needs for requests in GLX extension (CVE-2014-8093). * Integer overflows calculating memory needs for requests in DRI2 extension (CVE-2014-8094). * Out of bounds access due to not validating length or offset values in requests in XInput extension (CVE-2014-8095). * Out of bounds access due to not validating length or offset values in requests in XC-MISC extension (CVE-2014-8096). * Out of bounds access due to not validating length or offset values in requests in DBE extension (CVE-2014-8097). * Out of bounds access due to not validating length or offset values

References

#864911 #886213 #907268 #907633

Cross- CVE-2014-8091 CVE-2014-8092 CVE-2014-8093

CVE-2014-8094 CVE-2014-8095 CVE-2014-8096

CVE-2014-8097 CVE-2014-8098 CVE-2014-8099

CVE-2014-8100 CVE-2014-8101 CVE-2014-8102

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2014-8091.html

https://www.suse.com/security/cve/CVE-2014-8092.html

https://www.suse.com/security/cve/CVE-2014-8093.html

https://www.suse.com/security/cve/CVE-2014-8094.html

https://www.suse.com/security/cve/CVE-2014-8095.html

https://www.suse.com/security/cve/CVE-2014-8096.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0045-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here