Описание
Security update for xorg-x11-server
This update for xorg-x11-server fixes the following issues:
- CVE-2021-4008: Fixed Privilege Escalation Vulnerability via Out-Of-Bounds Access in SProcRenderCompositeGlyphs (bsc#1193030).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15-ESPOS
xorg-x11-server-1.19.6-8.33.1
xorg-x11-server-extra-1.19.6-8.33.1
xorg-x11-server-sdk-1.19.6-8.33.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
xorg-x11-server-1.19.6-8.33.1
xorg-x11-server-extra-1.19.6-8.33.1
xorg-x11-server-sdk-1.19.6-8.33.1
SUSE Linux Enterprise Server 15-LTSS
xorg-x11-server-1.19.6-8.33.1
xorg-x11-server-extra-1.19.6-8.33.1
xorg-x11-server-sdk-1.19.6-8.33.1
SUSE Linux Enterprise Server for SAP Applications 15
xorg-x11-server-1.19.6-8.33.1
xorg-x11-server-extra-1.19.6-8.33.1
xorg-x11-server-sdk-1.19.6-8.33.1
Ссылки
- Link for SUSE-SU-2021:4065-1
- E-Mail link for SUSE-SU-2021:4065-1
- SUSE Security Ratings
- SUSE Bug 1193030
- SUSE CVE CVE-2021-4008 page
Описание
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15-ESPOS:xorg-x11-server-1.19.6-8.33.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:xorg-x11-server-extra-1.19.6-8.33.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS:xorg-x11-server-sdk-1.19.6-8.33.1
SUSE Linux Enterprise High Performance Computing 15-LTSS:xorg-x11-server-1.19.6-8.33.1
Ссылки
- CVE-2021-4008
- SUSE Bug 1193030
- SUSE Bug 1194308
- SUSE Bug 1196656