QID 352377

Date Published: 2021-06-03

QID 352377: Amazon Linux Security Advisory for libX11: AL2012-2020-330

Package updates are available for amazon linux that fix the following vulnerabilities: cve-2020-14363: an integer overflow vulnerability leading to a double-free was found in libx11.
This flaw allows a local privileged attacker to cause an application compiled with libx11 to crash, or in some cases, result in arbitrary code execution.
The highest threat from this flaw is to confidentiality, integrity as well as system availability.
1872473: cve-2020-14363 libx11: integer overflow leads to double free in locale handling

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 352377

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2020-330 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html