{"id":110740,"date":"2023-10-11T15:10:19","date_gmt":"2023-10-11T13:10:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-bibliotekah-x-org-dve-iz-kotoryh-prisutstvuyut-s-1988-goda"},"modified":"2023-10-11T15:10:19","modified_gmt":"2023-10-11T13:10:19","slug":"uyazvimosti-v-bibliotekah-x-org-dve-iz-kotoryh-prisutstvuyut-s-1988-goda","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-bibliotekah-x-org-dve-iz-kotoryh-prisutstvuyut-s-1988-goda","title":{"rendered":"Vulnerabilidades en las bibliotecas de X.Org, dos de las cuales est\u00e1n presentes desde 1988","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se ha publicado informaci\u00f3n sobre cinco vulnerabilidades en las bibliotecas libX11 y libXpm, desarrolladas por el proyecto X.Org. Los problemas han sido corregidos en las versiones libXpm 3.5.17 y libX11 1.8.7. Tres vulnerabilidades se han detectado en la biblioteca libx11, que ofrece funciones con una implementaci\u00f3n de cliente para el protocolo X11:   <\/p>\n<ul>\n<li class=\"l\"> CVE-2023-43785 \u2014 desbordamiento de b\u00fafer en el c\u00f3digo de libX11, que se manifiesta al procesar la respuesta del servidor X con un n\u00famero de caracteres que no coincide con la solicitud previamente enviada por XkbGetMap. La vulnerabilidad es causada por un error en X11R6.1, que existe desde 1996. Puede ser explotada al conectar una aplicaci\u00f3n que utiliza libx11 a un servidor X malicioso o a un proxy intermedio controlado por un atacante.\n<li class=\"l\"> CVE-2023-43786 \u2014 agotamiento de pila debido a una recursi\u00f3n infinita en la funci\u00f3n PutSubImage() de libX11, que se produce al procesar datos especialmente formateados en el formato XPM. La vulnerabilidad ha existido desde el lanzamiento de X11R2 en febrero de 1988.\n<li class=\"l\"> CVE-2023-43787 \u2014 desbordamiento entero en la funci\u00f3n XCreateImage() de libX11, lo que lleva a un desbordamiento de heap debido a un error en el c\u00e1lculo del tama\u00f1o, que no coincide con el tama\u00f1o real de los datos. La funci\u00f3n problem\u00e1tica XCreateImage() es invocada desde la funci\u00f3n XpmReadFileToPixmap(), lo que permite explotar la vulnerabilidad al procesar un archivo especialmente formateado en formato XPM. Esta vulnerabilidad tambi\u00e9n ha existido desde el X11R2 (a\u00f1o 1988).    <\/ul>\n<p>Adem\u00e1s, se han revelado dos vulnerabilidades en la biblioteca libXpm (CVE-2023-43788 y CVE-2023-43789), causadas por la posibilidad de lectura desde \u00e1reas fuera de los l\u00edmites de la memoria asignada. Los problemas se manifiestan al cargar un comentario desde el b\u00fafer en memoria y al procesar un archivo XPM con un mapa de colores incorrecto. Ambas vulnerabilidades datan de 1998 y se descubrieron mediante el uso de herramientas de detecci\u00f3n de errores de memoria y pruebas de fuzzing como AddressSanitizer y libFuzzer.        <\/p>\n<p>X.org ha tenido problemas de seguridad hist\u00f3ricos, por ejemplo, hace diez a\u00f1os, en la 30\u00aa conferencia Chaos Communication Congress (CCC), en la presentaci\u00f3n del investigador de seguridad Ilja van Sprundel, la mitad de la presentaci\u00f3n estuvo dedicada a los problemas en <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/dts-newyork\/\"   title=\"servidor\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2764\">servidor<\/a> X.Org, y la otra mitad de la seguridad de las bibliotecas cliente de X11. En el informe de Ilya, que en 2013 identific\u00f3 30 vulnerabilidades que afectan a diversas bibliotecas cliente de X11, as\u00ed como a los componentes DRI de Mesa, hab\u00eda declaraciones emotivas como \u00ab\u00a1GLX es un terrible desmotivador! \u00a180,000 l\u00edneas de terror puro!\u00bb y \u00abEn los \u00faltimos meses he encontrado 120 errores en \u00e9l, y a\u00fan no he terminado la revisi\u00f3n!\u00bb.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59906\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u0431\u043d\u0430\u0440\u043e\u0434\u043e\u0432\u0430\u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e \u043f\u044f\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 libX11 \u0438 libXpm, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c X.Org. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 libXpm 3.5.17 \u0438 libX11 1.8.7. \u0422\u0440\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libx11, \u043f\u0440\u0435\u0434\u043b\u0430\u0433\u0430\u044e\u0449\u0435\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 \u0441 \u043a\u043b\u0438\u0435\u043d\u0442\u0441\u043a\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 X11: CVE-2023-43785 &#8212; \u0432\u044b\u0445\u043e\u0434 \u0437\u0430 \u0433\u0440\u0430\u043d\u0438\u0446\u044b \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u043a\u043e\u0434\u0435 libX11, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u043e\u0442\u0432\u0435\u0442\u0430 \u043e\u0442 X-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0441 \u0447\u0438\u0441\u043b\u043e\u043c \u0441\u0438\u043c\u0432\u043e\u043b\u043e\u0432, \u043d\u0435 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-110740","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u0431\u043d\u0430\u0440\u043e\u0434\u043e\u0432\u0430\u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e \u043f\u044f\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 libX11 \u0438 libXpm, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c X.Org. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 libXpm 3.5.17 \u0438 libX11 1.8.7.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-bibliotekah-x-org-dve-iz-kotoryh-prisutstvuyut-s-1988-goda\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 X.Org, \u0434\u0432\u0435 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0442 \u0441 1988 \u0433\u043e\u0434\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u0431\u043d\u0430\u0440\u043e\u0434\u043e\u0432\u0430\u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e \u043f\u044f\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 libX11 \u0438 libXpm, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c X.Org. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 libXpm 3.5.17 \u0438 libX11 1.8.7.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-bibliotekah-x-org-dve-iz-kotoryh-prisutstvuyut-s-1988-goda\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-10-11T13:10:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-10-11T13:10:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidades en las bibliotecas X.Org, dos de las cuales est\u00e1n presentes desde 1988 | ProHoster","description":"Se ha revelado informaci\u00f3n sobre cinco vulnerabilidades en las bibliotecas libX11 y libXpm, desarrolladas por el proyecto X.Org. Los problemas han sido corregidos en las versiones libXpm 3.5.17 y libX11 1.8.7.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-bibliotekah-x-org-dve-iz-kotoryh-prisutstvuyut-s-1988-goda","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 X.Org, \u0434\u0432\u0435 \u0438\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u044e\u0442 \u0441 1988 \u0433\u043e\u0434\u0430 | ProHoster","og:description":"\u041e\u0431\u043d\u0430\u0440\u043e\u0434\u043e\u0432\u0430\u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e \u043f\u044f\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u0432 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430\u0445 libX11 \u0438 libXpm, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c X.Org. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 libXpm 3.5.17 \u0438 libX11 1.8.7.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-bibliotekah-x-org-dve-iz-kotoryh-prisutstvuyut-s-1988-goda","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-10-11T13:10:19+00:00","article:modified_time":"2023-10-11T13:10:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"110740","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-09 21:40:03","updated":"2026-02-09 21:40:03","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=110740"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110740\/revisions"}],"predecessor-version":[{"id":160044,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110740\/revisions\/160044"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=110740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=110740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=110740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}