QID 356991
Date Published: 2024-01-17
QID 356991: Amazon Linux Security Advisory for xorg-x11-server : AL2012-2023-475
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2023-5380:
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.
CVE-2023-5367:
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
CVEs related to QID 356991
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-475 | Amazon Linux Bare Metal |
|