Vulnerabilities found in X.Org Server and libX11 :
- — lack of memory initialization when allocating buffers for pixmaps via the AllocatePixmap() call may result in an X client leaking heap memory contents when the X server runs with elevated privileges. This leak can be exploited to bypass Address Space Layout Randomization (ASLR). Combined with other vulnerabilities, this issue can be used to create an exploit for privilege escalation in the system. Fixes are currently available as patches.
of the corrective release of X.Org Server 1.20.9 is expected in the coming days. - — integer overflow in the XIM (Input Method) implementation in libX11, which may lead to memory corruption in the heap when processing specially crafted input method messages.
The issue has been resolved in the release .
Source: opennet.ru
