Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

openSUSE-SU-2016:3034-1

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 07 Π΄Π΅ΠΊ. 2016
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: suse-cvrf

ОписаниС

Security update for X Window System client libraries

This update for X Window System client libraries fixes a class of privilege escalation issues.

A malicious X server could send specially crafted data to X clients, which allowed for triggering crashes, or privilege escalation if this relationship was untrusted or crossed user or permission level boundaries.

The following libraries have been fixed:

libX11:

  • plugged a memory leak (boo#1002991, CVE-2016-7942).
  • insufficient validation of data from the X server can cause out of boundary memory read (XGetImage()) or write (XListFonts()) (boo#1002991, CVE-2016-7942).

libXi:

  • Integer overflows in libXi can cause out of boundary memory access or endless loops (Denial of Service) (boo#1002998, CVE-2016-7945).
  • Insufficient validation of data in libXi can cause out of boundary memory access or endless loops (Denial of Service) (boo#1002998, CVE-2016-7946).

libXrandr:

  • Insufficient validation of data from the X server can cause out of boundary memory writes (boo#1003000, CVE-2016-7947, CVE-2016-7948).

Бписок ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ²

openSUSE Leap 42.1
libX11-1.6.3-9.1
libX11-6-1.6.3-9.1
libX11-6-32bit-1.6.3-9.1
libX11-data-1.6.3-9.1
libX11-devel-1.6.3-9.1
libX11-devel-32bit-1.6.3-9.1
libX11-xcb1-1.6.3-9.1
libX11-xcb1-32bit-1.6.3-9.1
libXi-1.7.5-6.1
libXi-devel-1.7.5-6.1
libXi-devel-32bit-1.7.5-6.1
libXi6-1.7.5-6.1
libXi6-32bit-1.7.5-6.1
libXrandr-1.5.0-5.1
libXrandr-devel-1.5.0-5.1
libXrandr-devel-32bit-1.5.0-5.1
libXrandr2-1.5.0-5.1
libXrandr2-32bit-1.5.0-5.1
openSUSE Leap 42.2
libX11-1.6.3-9.1
libX11-6-1.6.3-9.1
libX11-6-32bit-1.6.3-9.1
libX11-data-1.6.3-9.1
libX11-devel-1.6.3-9.1
libX11-devel-32bit-1.6.3-9.1
libX11-xcb1-1.6.3-9.1
libX11-xcb1-32bit-1.6.3-9.1
libXi-1.7.5-6.1
libXi-devel-1.7.5-6.1
libXi-devel-32bit-1.7.5-6.1
libXi6-1.7.5-6.1
libXi6-32bit-1.7.5-6.1
libXrandr-1.5.0-5.1
libXrandr-devel-1.5.0-5.1
libXrandr-devel-32bit-1.5.0-5.1
libXrandr2-1.5.0-5.1
libXrandr2-32bit-1.5.0-5.1

Бсылки

ОписаниС

The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
openSUSE Leap 42.1:libX11-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-32bit-1.6.3-9.1
openSUSE Leap 42.1:libX11-data-1.6.3-9.1

Бсылки

ОписаниС

Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
openSUSE Leap 42.1:libX11-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-32bit-1.6.3-9.1
openSUSE Leap 42.1:libX11-data-1.6.3-9.1

Бсылки

ОписаниС

X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
openSUSE Leap 42.1:libX11-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-32bit-1.6.3-9.1
openSUSE Leap 42.1:libX11-data-1.6.3-9.1

Бсылки

ОписаниС

Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
openSUSE Leap 42.1:libX11-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-32bit-1.6.3-9.1
openSUSE Leap 42.1:libX11-data-1.6.3-9.1

Бсылки

ОписаниС

X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
openSUSE Leap 42.1:libX11-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-1.6.3-9.1
openSUSE Leap 42.1:libX11-6-32bit-1.6.3-9.1
openSUSE Leap 42.1:libX11-data-1.6.3-9.1

Бсылки
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ openSUSE-SU-2016:3034-1