QID 352281

Date Published: 2021-06-24

QID 352281: Amazon Linux Security Update for xorg-x11-server: ALAS2-2021-1633

<DIV ID="issue_overview">
A flaw was found in xorg-x11-server. An interger underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. (CVE-2021-3472 )
</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Please refer to Amazon advisory: ALAS-2021-1633 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 352281

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1633 Amazon Linux 2 URL Logo alas.aws.amazon.com/AL2/ALAS-2021-1633.html