Oval Definition:oval:com.redhat.rhsa:def:20192079
Revision Date:2019-08-06Version:638
Title:RHSA-2019:2079: Xorg security and bug fix update (Moderate)
Description:X.Org is an open-source implementation of the X Window System. It provides the basic low-level functionality that full-fledged graphical user interfaces are designed upon.

Security Fix(es):

  • libX11: Crash on invalid reply in XListExtensions in ListExt.c (CVE-2018-14598)

  • libX11: Off-by-one error in XListExtensions in ListExt.c (CVE-2018-14599)

  • libX11: Out of Bounds write in XListExtensions in ListExt.c (CVE-2018-14600)

  • libxkbcommon: Invalid free in ExprAppendMultiKeysymList resulting in a crash (CVE-2018-15857)

  • libxkbcommon: Endless recursion in xkbcomp/expr.c resulting in a crash (CVE-2018-15853)

  • libxkbcommon: NULL pointer dereference resulting in a crash (CVE-2018-15854)

  • libxkbcommon: NULL pointer dereference when handling xkb_geometry (CVE-2018-15855)

  • libxkbcommon: Infinite loop when reaching EOL unexpectedly resulting in a crash (CVE-2018-15856)

  • libxkbcommon: NULL pointer dereference when parsing invalid atoms in ExprResolveLhs resulting in a crash (CVE-2018-15859)

  • libxkbcommon: NULL pointer dereference in ExprResolveLhs resulting in a crash (CVE-2018-15861)

  • libxkbcommon: NULL pointer dereference in LookupModMask resulting in a crash (CVE-2018-15862)

  • libxkbcommon: NULL pointer dereference in ResolveStateAndPredicate resulting in a crash (CVE-2018-15863)

  • libxkbcommon: NULL pointer dereference in resolve_keysym resulting in a crash (CVE-2018-15864)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-14598
    CVE-2018-14599
    CVE-2018-14600
    CVE-2018-15853
    CVE-2018-15854
    CVE-2018-15855
    CVE-2018-15856
    CVE-2018-15857
    CVE-2018-15859
    CVE-2018-15861
    CVE-2018-15862
    CVE-2018-15863
    CVE-2018-15864
    RHSA-2019:2079
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • libxkbcommon is earlier than 0:0.7.1-3.el7
  • AND libxkbcommon is signed with Red Hat redhatrelease2 key
  • libxkbcommon-devel is earlier than 0:0.7.1-3.el7
  • AND libxkbcommon-devel is signed with Red Hat redhatrelease2 key
  • libxkbcommon-x11 is earlier than 0:0.7.1-3.el7
  • AND libxkbcommon-x11 is signed with Red Hat redhatrelease2 key
  • libxkbcommon-x11-devel is earlier than 0:0.7.1-3.el7
  • AND libxkbcommon-x11-devel is signed with Red Hat redhatrelease2 key
  • xorg-x11-drv-vesa is earlier than 0:2.4.0-3.el7
  • AND xorg-x11-drv-vesa is signed with Red Hat redhatrelease2 key
  • mesa-libGLw is earlier than 0:8.0.0-5.el7
  • AND mesa-libGLw is signed with Red Hat redhatrelease2 key
  • mesa-libGLw-devel is earlier than 0:8.0.0-5.el7
  • AND mesa-libGLw-devel is signed with Red Hat redhatrelease2 key
  • gdm is earlier than 1:3.28.2-16.el7
  • AND gdm is signed with Red Hat redhatrelease2 key
  • gdm-devel is earlier than 1:3.28.2-16.el7
  • AND gdm-devel is signed with Red Hat redhatrelease2 key
  • gdm-pam-extensions-devel is earlier than 1:3.28.2-16.el7
  • AND gdm-pam-extensions-devel is signed with Red Hat redhatrelease2 key
  • libX11 is earlier than 0:1.6.7-2.el7
  • AND libX11 is signed with Red Hat redhatrelease2 key
  • libX11-common is earlier than 0:1.6.7-2.el7
  • AND libX11-common is signed with Red Hat redhatrelease2 key
  • libX11-devel is earlier than 0:1.6.7-2.el7
  • AND libX11-devel is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-Xdmx is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-Xdmx is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-Xephyr is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-Xephyr is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-Xnest is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-Xnest is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-Xorg is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-Xorg is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-Xvfb is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-Xvfb is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-Xwayland is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-Xwayland is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-common is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-common is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-devel is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-devel is signed with Red Hat redhatrelease2 key
  • xorg-x11-server-source is earlier than 0:1.20.4-7.el7
  • AND xorg-x11-server-source is signed with Red Hat redhatrelease2 key
  • xorg-x11-drv-ati is earlier than 0:19.0.1-2.el7
  • AND xorg-x11-drv-ati is signed with Red Hat redhatrelease2 key
  • xorg-x11-drv-wacom is earlier than 0:0.36.1-3.el7
  • AND xorg-x11-drv-wacom is signed with Red Hat redhatrelease2 key
  • xorg-x11-drv-wacom-devel is earlier than 0:0.36.1-3.el7
  • AND xorg-x11-drv-wacom-devel is signed with Red Hat redhatrelease2 key
  • BACK