]> code.ossystems Code Review - openembedded-core.git/commit
libx11: Fix CVE-2021-31535
authorJasper Orschulko <jasper@fancydomain.eu>
Tue, 22 Jun 2021 14:54:16 +0000 (16:54 +0200)
committerSteve Sakoman <steve@sakoman.com>
Sun, 27 Jun 2021 19:24:24 +0000 (09:24 -1000)
commit81d338c6079729b35f55f8889526f0c9a62802fe
tree5cee058c3eb81f6d4861b036bec33ca9ee43fc03
parentef2a81a473e7c36a36facb209ca907a7439d36f2
libx11: Fix CVE-2021-31535

https://lists.x.org/archives/xorg-announce/2021-May/003088.html

XLookupColor() and other X libraries function lack proper validation
of the length of their string parameters. If those parameters can be
controlled by an external application (for instance a color name that
can be emitted via a terminal control sequence) it can lead to the
emission of extra X protocol requests to the X server.

Signed-off-by: Jasper Orschulko <jasper@fancydomain.eu>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-graphics/xorg-lib/libx11/CVE-2021-31535.patch [new file with mode: 0644]
meta/recipes-graphics/xorg-lib/libx11_1.6.9.bb