[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2018:3102-1 -- SLES libX11, libxcb

ID: oval:org.secpod.oval:def:89002308Date: (C)2021-02-26   (M)2023-03-08
Class: PATCHFamily: unix




This update for libX11 and libxcb fixes the following issue: libX11: These security issues were fixed: - CVE-2018-14599: The function XListExtensions was vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact . - CVE-2018-14600: The function XListExtensions interpreted a variable as signed instead of unsigned, resulting in an out-of-bounds write , leading to DoS or remote code execution . - CVE-2018-14598: A malicious server could have sent a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS . This non-security issue was fixed: - Make use of the new 64-bit sequence number API in XCB 1.11.1 to avoid the 32-bit sequence number wrap in libX11 . libxcb: - Expose 64-bit sequence number from XCB API so that Xlib and others can use it even on 32-bit environment

Platform:
SUSE Linux Enterprise Server 12 SP3
Product:
libX11
libxcb
Reference:
SUSE-SU-2018:3102-1
CVE-2018-14598
CVE-2018-14599
CVE-2018-14600
CVE    3
CVE-2018-14599
CVE-2018-14598
CVE-2018-14600
CPE    3
cpe:/o:suse:suse_linux_enterprise_server:12:sp3
cpe:/a:x:libX11
cpe:/a:x:libxcb

© SecPod Technologies