Описание
Security update for xorg-x11-server
This update for xorg-x11-server fixes the following issues:
- CVE-2023-6816: Fixed heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer (bsc#1218582)
- CVE-2024-0229: Fixed reattaching to different master device may lead to out-of-bounds memory access (bsc#1218583)
- CVE-2024-21885: Fixed heap buffer overflow in XISendDeviceHierarchyEvent (bsc#1218584)
- CVE-2024-21886: Fixed heap buffer overflow in DisableDevice (bsc#1218585)
Список пакетов
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP5
Ссылки
- Link for SUSE-SU-2024:0116-1
- E-Mail link for SUSE-SU-2024:0116-1
- SUSE Security Ratings
- SUSE Bug 1218582
- SUSE Bug 1218583
- SUSE Bug 1218584
- SUSE Bug 1218585
- SUSE CVE CVE-2023-6816 page
- SUSE CVE CVE-2024-0229 page
- SUSE CVE CVE-2024-21885 page
- SUSE CVE CVE-2024-21886 page
Описание
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.
Затронутые продукты
Ссылки
- CVE-2023-6816
- SUSE Bug 1218582
- SUSE Bug 1221590
Описание
An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution in SSH X11 forwarding environments.
Затронутые продукты
Ссылки
- CVE-2024-0229
- SUSE Bug 1218583
- SUSE Bug 1221590
Описание
A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array length when certain new device IDs are added to the xXIHierarchyInfo struct. This can trigger a heap buffer overflow condition, which may lead to an application crash or remote code execution in SSH X11 forwarding environments.
Затронутые продукты
Ссылки
- CVE-2024-21885
- SUSE Bug 1218584
- SUSE Bug 1221590
Описание
A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in some circumstances, remote code execution in SSH X11 forwarding environments.
Затронутые продукты
Ссылки
- CVE-2024-21886
- SUSE Bug 1218585
- SUSE Bug 1221590