what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Xlibre Xnest 24.1.0 / 24.2.0 Buffer Overflow

Xlibre Xnest 24.1.0 / 24.2.0 Buffer Overflow
Posted Nov 1, 2024
Authored by Enrico Weigelt

Xlibre Xnest versions 24.1.0 and 24.2.0 suffer from a buffer overflow vulnerability that affected Xorg.

tags | advisory, overflow
advisories | CVE-2024-9632
SHA-256 | e1d1c90f3bed32a3621cdec6499a0799dd3782078452bf7dc1d063ca25c1e2f0

Xlibre Xnest 24.1.0 / 24.2.0 Buffer Overflow

Change Mirror Download
XLibre project security advisory
---------------------------------

As Xlibre Xnest is based on Xorg, it is affected by some security issues
which recently became known in Xorg:

CVE-2024-9632: can be triggered by providing a modified bitmap to the
X.Org server.
CVE-2024-9632: Heap-based buffer overflow privilege escalation in
_XkbSetCompatMap

See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9632


Affected versions:

* 24.1.0
* 24.2.0


24.1.x release:

Repo: https://gitlab.freedesktop.org/metux/xserver.git
Branch: xlibre/xnest/24.1
Tag: xnest-24.1.1
SHA: 11450b0946c1035944c5946d665f21f83356b6b9

24.2.x release:

Repo: https://gitlab.freedesktop.org/metux/xserver.git
Branch: xlibre/xnest/24.2
Tag: xnest-24.2.1
SHA: 9a6aec9bf62b6bdd75795a5e28648d4af07fe413


These bugfix branches also contain several other pointer and bounds
related problems that haven't been rated as possibly exploitable yet,
but no other unnecessary changes which don't fix actual bugs.

All users are strongly advised to upgrade to the fixed mainenance
releases ASAP.


--mtx

--
---
Enrico Weigelt, metux IT consult
Free software and Linux embedded engineering
info@metux.net -- +49-151-27565287

Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close