Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:2372-1

Опубликовано: 12 июл. 2022
Источник: suse-cvrf

Описание

Security update for xorg-x11-server

This update for xorg-x11-server fixes the following issues:

  • CVE-2022-2319: Fixed out-of-bounds access in _CheckSetSections() (ZDI-CAN-16062) (bsc#1194179).
  • CVE-2022-2320: Fixed out-of-bounds access in CheckSetDeviceIndicators() (ZDI-CAN-16070) (bsc#1194181).

Список пакетов

SUSE Linux Enterprise Server 12 SP2-BCL
xorg-x11-server-7.6_1.18.3-76.49.1
xorg-x11-server-extra-7.6_1.18.3-76.49.1
SUSE Linux Enterprise Server 12 SP3-BCL
xorg-x11-server-7.6_1.18.3-76.49.1
xorg-x11-server-extra-7.6_1.18.3-76.49.1

Описание

A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due to improper validation of the request length.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:xorg-x11-server-7.6_1.18.3-76.49.1
SUSE Linux Enterprise Server 12 SP2-BCL:xorg-x11-server-extra-7.6_1.18.3-76.49.1
SUSE Linux Enterprise Server 12 SP3-BCL:xorg-x11-server-7.6_1.18.3-76.49.1
SUSE Linux Enterprise Server 12 SP3-BCL:xorg-x11-server-extra-7.6_1.18.3-76.49.1

Ссылки

Описание

A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. This flaw allows an attacker to escalate privileges and execute arbitrary code in the context of root.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:xorg-x11-server-7.6_1.18.3-76.49.1
SUSE Linux Enterprise Server 12 SP2-BCL:xorg-x11-server-extra-7.6_1.18.3-76.49.1
SUSE Linux Enterprise Server 12 SP3-BCL:xorg-x11-server-7.6_1.18.3-76.49.1
SUSE Linux Enterprise Server 12 SP3-BCL:xorg-x11-server-extra-7.6_1.18.3-76.49.1

Ссылки
Уязвимость SUSE-SU-2022:2372-1