Описание
Security update for xorg-x11-server
This update for xorg-x11-server fixes the following issues:
- CVE-2021-4011: The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to out of bounds memory write. (bsc#1190489)
Список пакетов
SUSE Linux Enterprise Point of Sale 11 SP3
xorg-x11-Xvnc-7.4-27.122.46.1
xorg-x11-server-7.4-27.122.46.1
xorg-x11-server-extra-7.4-27.122.46.1
SUSE Linux Enterprise Server 11 SP4-LTSS
xorg-x11-Xvnc-7.4-27.122.46.1
xorg-x11-server-7.4-27.122.46.1
xorg-x11-server-extra-7.4-27.122.46.1
Ссылки
- Link for SUSE-SU-2021:14867-1
- E-Mail link for SUSE-SU-2021:14867-1
- SUSE Security Ratings
- SUSE Bug 1190489
- SUSE CVE CVE-2021-4011 page
Описание
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:xorg-x11-Xvnc-7.4-27.122.46.1
SUSE Linux Enterprise Point of Sale 11 SP3:xorg-x11-server-7.4-27.122.46.1
SUSE Linux Enterprise Point of Sale 11 SP3:xorg-x11-server-extra-7.4-27.122.46.1
SUSE Linux Enterprise Server 11 SP4-LTSS:xorg-x11-Xvnc-7.4-27.122.46.1
Ссылки
- CVE-2021-4011
- SUSE Bug 1190489
- SUSE Bug 1196656