Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201711-05 ] X.Org Server: Multiple vulnerabilities
Date: Fri, 10 Nov 2017 23:43:01
Message-Id: 2048686.JyS3eqMfnQ@localhost.localdomain
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201711-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: X.Org Server: Multiple vulnerabilities
9 Date: November 10, 2017
10 Bugs: #635974
11 ID: 201711-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in X.Org Server, the worst of
19 which could allow an attacker to execute arbitrary code.
20
21 Background
22 ==========
23
24 The X.Org project provides an open source implementation of the X
25 Window System.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 x11-base/xorg-server < 1.19.5 >= 1.19.5
34
35 Description
36 ===========
37
38 Multiple vulnerabilities have been discovered in X.Org Server. Please
39 review the referenced CVE identifiers for details.
40
41 Impact
42 ======
43
44 Attackers could execute arbitrary code or cause a Denial of Service
45 condition.
46
47 Workaround
48 ==========
49
50 There is now know workaround at this time.
51
52 Resolution
53 ==========
54
55 All X.Org Server users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot --verbose ">=x11-base/xorg-server-1.19.5"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2017-12176
64 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12176
65 [ 2 ] CVE-2017-12177
66 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12177
67 [ 3 ] CVE-2017-12178
68 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12178
69 [ 4 ] CVE-2017-12179
70 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12179
71 [ 5 ] CVE-2017-12180
72 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12180
73 [ 6 ] CVE-2017-12181
74 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12181
75 [ 7 ] CVE-2017-12182
76 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12182
77 [ 8 ] CVE-2017-12183
78 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12183
79
80 Availability
81 ============
82
83 This GLSA and any updates to it are available for viewing at
84 the Gentoo Security Website:

Attachments

File name MIME type
signature.asc application/pgp-signature