ALT-BU-2020-4039-1
Branch p9 update bulletin.
Closed vulnerabilities
BDU:2021-02599
Уязвимость библиотеки предоставления клиентского API для X Window System libX11, связанная с использованием памяти после ее освобождения, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2024-11-21
CVE-2020-14363
An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary code execution. The highest threat from this flaw is to confidentiality, integrity as well as system availability.
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14363
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14363
- https://github.com/Ruia-ruia/Exploits/blob/master/DFX11details.txt
- https://github.com/Ruia-ruia/Exploits/blob/master/DFX11details.txt
- https://github.com/Ruia-ruia/Exploits/blob/master/x11doublefree.sh
- https://github.com/Ruia-ruia/Exploits/blob/master/x11doublefree.sh
- FEDORA-2020-cf0afbd27e
- FEDORA-2020-cf0afbd27e
- https://lists.x.org/archives/xorg-announce/2020-August/003056.html
- https://lists.x.org/archives/xorg-announce/2020-August/003056.html
- USN-4487-2
- USN-4487-2
Package xorg-server updated to version 1.20.8-alt4 for branch p9 in task 258208.
Closed vulnerabilities
BDU:2020-03504
Уязвимость библиотеки шрифтов операционных систем Windows, позволяющая нарушителю выполнить произвольный код
BDU:2021-00127
Уязвимость функции SProcXkbSelectEvents сервера X Window System Xorg-server, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-00128
Уязвимость функции ProcXIChangeHierarchy сервера X Window System Xorg-server, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-14346
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- https://bugzilla.redhat.com/show_bug.cgi?id=1862246
- https://bugzilla.redhat.com/show_bug.cgi?id=1862246
- https://lists.x.org/archives/xorg-announce/2020-August/003058.html
- https://lists.x.org/archives/xorg-announce/2020-August/003058.html
- GLSA-202012-01
- GLSA-202012-01
- USN-4488-2
- USN-4488-2
- https://www.zerodayinitiative.com/advisories/ZDI-20-1417/
- https://www.zerodayinitiative.com/advisories/ZDI-20-1417/
Modified: 2024-11-21
CVE-2020-1436
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
- [oss-security] 20200825 X.Org server security advisory: August 25, 2020
- [oss-security] 20200825 X.Org server security advisory: August 25, 2020
- [oss-security] 20200825 Re: X.Org server security advisory: August 25, 2020
- [oss-security] 20200825 Re: X.Org server security advisory: August 25, 2020
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1436
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1436
- https://www.zerodayinitiative.com/advisories/ZDI-20-877/
- https://www.zerodayinitiative.com/advisories/ZDI-20-877/
Modified: 2024-11-21
CVE-2020-14361
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- https://bugzilla.redhat.com/show_bug.cgi?id=1869142
- https://bugzilla.redhat.com/show_bug.cgi?id=1869142
- https://lists.x.org/archives/xorg-announce/2020-August/003058.html
- https://lists.x.org/archives/xorg-announce/2020-August/003058.html
- GLSA-202012-01
- GLSA-202012-01
- USN-4488-2
- USN-4488-2
- https://www.zerodayinitiative.com/advisories/ZDI-20-1418/
- https://www.zerodayinitiative.com/advisories/ZDI-20-1418/