rpm package
almalinux/libX11-xcb
pkg:rpm/almalinux/libX11-xcb
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-43787 | — | < 1.7.0-9.el9 | 1.7.0-9.el9 | Oct 10, 2023 | A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges. | ||
| CVE-2023-43786 | — | < 1.7.0-9.el9 | 1.7.0-9.el9 | Oct 10, 2023 | A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition. | ||
| CVE-2023-43785 | — | < 1.7.0-9.el9 | 1.7.0-9.el9 | Oct 10, 2023 | A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system. | ||
| CVE-2023-3138 | — | < 1.7.0-8.el9 | 1.7.0-8.el9 | Jun 28, 2023 | A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array in | ||
| CVE-2021-31535 | — | < 1.6.8-5.el8 | 1.6.8-5.el8 | May 27, 2021 | LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the |
- CVE-2023-43787Oct 10, 2023affected < 1.7.0-9.el9fixed 1.7.0-9.el9
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
- CVE-2023-43786Oct 10, 2023affected < 1.7.0-9.el9fixed 1.7.0-9.el9
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
- CVE-2023-43785Oct 10, 2023affected < 1.7.0-9.el9fixed 1.7.0-9.el9
A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system.
- CVE-2023-3138Jun 28, 2023affected < 1.7.0-8.el9fixed 1.7.0-8.el9
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array in
- CVE-2021-31535May 27, 2021affected < 1.6.8-5.el8fixed 1.6.8-5.el8
LookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11 XLookupColor request (intended for server-side color lookup) contains a flaw allowing a client to send color-name requests with a name longer than the