Package "libx11-6"
Name: |
libx11-6
|
Description: |
X11 client-side library
|
Latest version: |
2:1.6.3-1ubuntu2.2 |
Release: |
xenial (16.04) |
Level: |
security |
Repository: |
main |
Head package: |
libx11 |
Links
Download "libx11-6"
Other versions of "libx11-6" in Xenial
Changelog
libx11 (2:1.6.3-1ubuntu2.2) xenial-security; urgency=medium
* SECURITY UPDATE: integer overflow and heap overflow in XIM client
- debian/patches/CVE-2020-14344-1.patch: fix signed length values in
modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-2.patch: fix integer overflows in
modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-3.patch: fix more unchecked lengths in
modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-4.patch: zero out buffers in functions
in modules/im/ximcp/imDefIc.c, modules/im/ximcp/imDefIm.c.
- debian/patches/CVE-2020-14344-5.patch: change the data_len parameter
to CARD16 in modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-6.patch: fix size calculation in
modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-7.patch: fix input clients connecting
to server in modules/im/ximcp/imRmAttr.c.
- CVE-2020-14344
* SECURITY UPDATE: integer overflow and double free in locale handling
- debian/patches/CVE-2020-14363.patch: fix an integer overflow in
modules/om/generic/omGeneric.c.
- CVE-2020-14363
-- Marc Deslauriers <email address hidden> Mon, 31 Aug 2020 12:11:23 -0400
|
Source diff to previous version |
CVE-2020-14344 |
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. A |
CVE-2020-14363 |
Double free in libX11 locale handling code |
|
libx11 (2:1.6.3-1ubuntu2.1) xenial-security; urgency=medium
* SECURITY UPDATE: Out-of-bounds read
- debian/patches/CVE-2016-7942.patch: fix in src/GetImage.c.
- CVE-2016-7942
* SECURITY UPDATE: Out-of-bounds read
- debian/patches/CVE-2016-7943.patch: fix in src/FontNames.c,
src/ListExt.c, src/ModMap.c.
- CVE-2016-7943
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2018-14598.patch: fix in src/GetFPath.c,
src/ListExt.c.
- CVE-2018-14598
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2018-14599.patch: fix in src/FontNames.c,
src/GetFPath.c, src/ListExt.c.
- CVE-2018-14599
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2018-14600.patch: fix in src/GetFPath.
- CVE-2018-14600
-- <email address hidden> (Leonidas S. Barbosa) Wed, 29 Aug 2018 17:04:57 -0300
|
CVE-2016-7942 |
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, wh |
CVE-2016-7943 |
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigg |
CVE-2018-14598 |
An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overfl |
CVE-2018-14599 |
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious s |
CVE-2018-14600 |
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resul |
|
About
-
Send Feedback to @ubuntu_updates