X.Org Server 21.1.4 update addressing vulnerabilities

A corrective release of X.Org Server 21.1.4 is now available, addressing two vulnerabilities in the Xkb extension handlers that allow privilege escalation on the system if the X server runs with root rights or to execute code on a remote system when accessing it through SSH session forwarding. The vulnerabilities stem from a lack of proper size checks in the ProcXkbSetGeometry (CVE-2022-2319) and ProcXkbSetDeviceInfo (CVE-2022-2320) request handlers, which can be exploited to write to memory outside the allocated buffer.

In the case of ProcXkbSetGeometry, the absence of size checks in the request fields allowed the client to trigger a buffer overflow by specifying a number of sections that did not match the actual data sent. In the ProcXkbSetDeviceInfo handler, the vulnerability arose from the incorrect order of function calls—the parameter checking function was called after the function that used those parameters (the function names were swapped and XkbSetDeviceInfo included the code for checking, while XkbSetDeviceInfoCheck was for setting values).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster