xorg-x11-server-1.20.4-17.el7

エラータID: AXSA:2022-2893:01

Release date: 
Wednesday, January 5, 2022 - 10:01
Subject: 
xorg-x11-server-1.20.4-17.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.

Security Fix(es):

* xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access (CVE-2021-4008)
* xorg-x11-server: SProcXFixesCreatePointerBarrier out-of-bounds access (CVE-2021-4009)
* xorg-x11-server: SProcScreenSaverSuspend out-of-bounds access (CVE-2021-4010)
* xorg-x11-server: SwapCreateRegister out-of-bounds access (CVE-2021-4011)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2021-4008
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-4009
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-4010
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVE-2021-4011
A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. xorg-x11-server-1.20.4-17.el7.src.rpm
    MD5: d854f6278a3c17a39965421d225f17d8
    SHA-256: f8ccfa606951a26dc8b7d4235fb2f2fc6a979871242400c2340d2b06e6ffd63c
    Size: 5.93 MB

Asianux Server 7 for x86_64
  1. xorg-x11-server-common-1.20.4-17.el7.x86_64.rpm
    MD5: 8d8863d3d2970ed5df4f3c7624fc2a61
    SHA-256: 9f2b7a19ce9cf77ac625d9224d8074e163186deebd4269df377c70f5e283bf8e
    Size: 55.07 kB
  2. xorg-x11-server-Xephyr-1.20.4-17.el7.x86_64.rpm
    MD5: e1a022616e4a7c1261b72c7186614314
    SHA-256: c087dd32b7b8153a91acc5f4271a0177e0ad7937b1b1360f781051460671be6b
    Size: 0.98 MB
  3. xorg-x11-server-Xorg-1.20.4-17.el7.x86_64.rpm
    MD5: ff35fb9817d36b1e989d840555fad386
    SHA-256: 257182ab8646d2296872ebe1cf6436a2f3dba278acf41cbed722f2d1c418e194
    Size: 1.45 MB
  4. xorg-x11-server-Xwayland-1.20.4-17.el7.x86_64.rpm
    MD5: c6bd3bd611866f90f0349ccdc6b032ca
    SHA-256: 9ef454ef4bcd8c2a18d028449ecd60175454d66c11ee6330228b6e31d49075d8
    Size: 950.11 kB