[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:3685-1 -- SLES libxkbcommon

ID: oval:org.secpod.oval:def:89049780Date: (C)2023-12-20   (M)2023-12-20
Class: PATCHFamily: unix




This update for libxkbcommon to version 0.8.2 fixes the following issues: - Fix a few NULL-dereferences, out-of-bounds access and undefined behavior in the XKB text format parser. - CVE-2018-15853: Endless recursion could have been used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation . - CVE-2018-15854: Unchecked NULL pointer usage could have been used by local attackers to crash the xkbcommon parser by supplying a crafted keymap file, because geometry tokens were desupported incorrectly . - CVE-2018-15855: Unchecked NULL pointer usage could have been used by local attackers to crash the xkbcommon parser by supplying a crafted keymap file, because the XkbFile for an xkb_geometry section was mishandled . - CVE-2018-15856: An infinite loop when reaching EOL unexpectedly could be used by local attackers to cause a denial of service during parsing of crafted keymap files . - CVE-2018-15857: An invalid free in ExprAppendMultiKeysymList could have been used by local attackers to crash xkbcommon keymap parsers or possibly have unspecified other impact by supplying a crafted keymap file . - CVE-2018-15858: Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap could have been used by local attackers to crash the xkbcommon parser by supplying a crafted keymap file . - CVE-2018-15859: Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs could have been used by local attackers to crash the xkbcommon parser by supplying a crafted keymap file, because lookup failures are mishandled . - CVE-2018-15861: Unchecked NULL pointer usage in ExprResolveLhs could have been used by local attackers to crash the xkbcommon parser by supplying a crafted keymap file that triggers an xkb_intern_atom failure . - CVE-2018-15862: Unchecked NULL pointer usage in LookupModMask could have been used by local attackers to crash the xkbcommon parser by supplying a crafted keymap file with invalid virtual modifiers . - CVE-2018-15863: Unchecked NULL pointer usage in ResolveStateAndPredicate could have been used by local attackers to crash the xkbcommon parser by supplying a crafted keymap file with a no-op modmask expression . - CVE-2018-15864: Unchecked NULL pointer usage in resolve_keysym could have been used by local attackers to crash the xkbcommon parser by supplying a crafted keymap file, because a map access attempt can occur for a map that was never created .

Platform:
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
Product:
libxkbcommon
Reference:
SUSE-SU-2018:3685-1
CVE-2018-15853
CVE-2018-15854
CVE-2018-15855
CVE-2018-15856
CVE-2018-15857
CVE-2018-15858
CVE-2018-15859
CVE-2018-15861
CVE-2018-15862
CVE-2018-15863
CVE-2018-15864
CVE    11
CVE-2018-15857
CVE-2018-15856
CVE-2018-15859
CVE-2018-15858
...
CPE    2
cpe:/a:x:libxkbcommon
cpe:/o:suse:suse_linux_enterprise_server:15

© SecPod Technologies