Several significant out-of-bounds access vulnerabilities have been found in the X.Org X Server (CVE-2021-4008, CVE-2021-4009, and CVE-2021-4011). These flaws threaten data confidentiality and integrity, as well as system availability, and have received a National Vulnerability Database severity rating of “High”. . An attacker could exploit these bugs to cause the server to crash, resulting in a denial of service (DoS), or possibly execute arbitrary code and escalate privileges. An update is available for X.Org that fixes these issues. We urge all impacted users to apply the updates issued by their distro(s) as soon as possible to protect their sensitive data and ensure their crucial systems remain accessible. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Significant flaws in the X.Org server may lead to data leaks and disruptions in service; patches have been released.. X.Org, DoS, Code Execution, Data Breaches, Security Updates. . Brittany Day
Several important security vulnerabilities have been found in the c-ares fork of the ares library, including a 0-byte UDP payload denial of service (DoS) bug (CVE-2023-32067). With low attack complexity, no privileges or user interaction required to exploit, and a high availability impact, this flaw has received a National Vulnerability Database (NVD) base score of 7.5 out of 10 (“High” severity). . These issues could lead to downtime due to loss of access to impacted systems. An important update for c-ares that mitigates these bugs has been released. We urge all impacted users to apply the c-ares updates issued by their distro(s) immediately to protect the availability of their critical systems. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . A crucial patch for c-ares addresses a critical DoS vulnerability classified as high risk. Users are urged to act promptly.. c-ares update, DoS bug fix, security mitigation, vulnerability management. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.