[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2016:2828-1 -- SLES libX11-debugsource, libX11-6, libX11-xcb1, libXfixes-debugsource, libXfixes3, libXi-debugsource, libXi6, libXrender-debugsource, libXrender1, libXtst-debugsource, libXtst6, libXv-debugsource, libXv1, libXvMC-debugsource, libXvMC1, libX11-data

ID: oval:org.secpod.oval:def:89045213Date: (C)2021-08-03   (M)2021-11-09
Class: PATCHFamily: unix




This update for the X Window System client libraries fixes a class of privilege escalation issues. A malicious X Server could send specially crafted data to X clients, which allowed for triggering crashes, or privilege escalation if this relationship was untrusted or crossed user or permission level boundaries. libX11, libXfixes, libXi, libXrandr, libXrender, libXtst, libXv, libXvMC were fixed, specifically: libX11: - CVE-2016-7942: insufficient validation of data from the X server allowed out of boundary memory read libXfixes: - CVE-2016-7944: insufficient validation of data from the X server can cause an integer overflow on 32 bit architectures libXi: - CVE-2016-7945, CVE-2016-7946: insufficient validation of data from the X server can cause out of boundary memory access or endless loops libXtst: - CVE-2016-7951, CVE-2016-7952: insufficient validation of data from the X server can cause out of boundary memory access or endless loops libXv: - CVE-2016-5407: insufficient validation of data from the X server can cause out of boundary memory and memory corruption libXvMC: - CVE-2016-7953: insufficient validation of data from the X server can cause a one byte buffer read underrun libXrender: - CVE-2016-7949, CVE-2016-7950: insufficient validation of data from the X server can cause out of boundary memory writes libXrandr: - CVE-2016-7947, CVE-2016-7948: insufficient validation of data from the X server can cause out of boundary memory writes

Platform:
SUSE Linux Enterprise Server 12 SP2
Product:
libX11-debugsource
libX11-6
libX11-xcb1
libXfixes-debugsource
libXfixes3
libXi-debugsource
libXi6
libXrender-debugsource
libXrender1
libXtst-debugsource
libXtst6
libXv-debugsource
libXv1
libXvMC-debugsource
libXvMC1
libX11-data
Reference:
SUSE-SU-2016:2828-1
CVE-2016-5407
CVE-2016-7942
CVE-2016-7944
CVE-2016-7945
CVE-2016-7946
CVE-2016-7947
CVE-2016-7948
CVE-2016-7949
CVE-2016-7950
CVE-2016-7951
CVE-2016-7952
CVE-2016-7953
CVE    12
CVE-2016-5407
CVE-2016-7942
CVE-2016-7949
CVE-2016-7947
...
CPE    1
cpe:/o:suse:suse_linux_enterprise_server:12:sp2

© SecPod Technologies