From 7b7fdd5a86cd28fc118fb133c98e81e2b15e0b92 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Wed, 31 Jan 2024 11:33:19 +0000 Subject: [ GLSA 202401-30 ] X.Org X Server, XWayland: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/916254 Bug: https://bugs.gentoo.org/919803 Bug: https://bugs.gentoo.org/922395 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202401-30.xml | 64 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 64 insertions(+) create mode 100644 glsa-202401-30.xml diff --git a/glsa-202401-30.xml b/glsa-202401-30.xml new file mode 100644 index 00000000..527cd4cf --- /dev/null +++ b/glsa-202401-30.xml @@ -0,0 +1,64 @@ + + + + X.Org X Server, XWayland: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation or remote code execution. + xorg-server,xwayland + 2024-01-31 + 2024-01-31 + 916254 + 919803 + 922395 + remote + + + 21.1.11 + 21.1.11 + + + 23.2.4 + 23.2.4 + + + +

The X Window System is a graphical windowing system based on a client/server model.

+
+ +

Multiple vulnerabilities have been discovered in X.Org X Server and XWayland. Please review the CVE identifiers referenced below for details.

+
+ +

The X server can be crashed by a malicious client, or potentially be compromised for remote code execution in environments with X11 forwarding.

+
+ +

Users can ensure no untrusted clients can access the running X implementation.

+
+ +

All X.Org X Server users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=x11-base/xorg-server-21.1.11" + + +

All XWayland users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=x11-base/xwayland-23.2.4" + +
+ + CVE-2023-5367 + CVE-2023-5380 + CVE-2023-6377 + CVE-2023-6478 + CVE-2023-6816 + CVE-2024-0229 + CVE-2024-0408 + CVE-2024-0409 + CVE-2024-21885 + CVE-2024-21886 + + ajak + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad