Lucene search

K
suseSuseOPENSUSE-SU-2020:1279-1
HistoryAug 29, 2020 - 12:00 a.m.

Security update for xorg-x11-server (important)

2020-08-2900:00:00
lists.opensuse.org
41

0.0005 Low

EPSS

Percentile

18.1%

An update that fixes three vulnerabilities is now available.

Description:

This update for xorg-x11-server fixes the following issues:

  • CVE-2020-14347: Leak of uninitialized heap memory from the X server to
    clients on pixmap allocation (bsc#1174633, ZDI-CAN-11426).
  • CVE-2020-14346: XIChangeHierarchy Integer Underflow Privilege Escalation
    Vulnerability (bsc#1174638, ZDI-CAN-11429).
  • CVE-2020-14345: XKB out-of-bounds access privilege escalation
    vulnerability (bsc#1174635, ZDI-CAN-11428).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.1:

    zypper in -t patch openSUSE-2020-1279=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.1i586< - openSUSE Leap 15.1 (i586 x86_64):- openSUSE Leap 15.1 (i586 x86_64):.i586.rpm
openSUSE Leap15.1x86_64< - openSUSE Leap 15.1 (i586 x86_64):- openSUSE Leap 15.1 (i586 x86_64):.x86_64.rpm