ALAS-2023-1859

Related Vulnerabilities: CVE-2023-43785   CVE-2023-43787  

libX11: out-of-bounds memory access in _XkbReadKeySyms() (CVE-2023-43785) libX11: integer overflow in XCreateImage() leading to a heap overflow. (CVE-2023-43787)

ALAS-2023-1859


Amazon Linux 1 Security Advisory: ALAS-2023-1859
Advisory Release Date: 2023-10-12 15:48 Pacific
Advisory Updated Date: 2023-10-24 21:38 Pacific
Severity: Medium

Issue Overview:

libX11: out-of-bounds memory access in _XkbReadKeySyms() (CVE-2023-43785)

libX11: integer overflow in XCreateImage() leading to a heap overflow. (CVE-2023-43787)


Affected Packages:

libX11


Issue Correction:
Run yum update libX11 to update your system.

New Packages:
i686:
    libX11-devel-1.6.0-2.2.16.amzn1.i686
    libX11-common-1.6.0-2.2.16.amzn1.i686
    libX11-1.6.0-2.2.16.amzn1.i686
    libX11-debuginfo-1.6.0-2.2.16.amzn1.i686

src:
    libX11-1.6.0-2.2.16.amzn1.src

x86_64:
    libX11-debuginfo-1.6.0-2.2.16.amzn1.x86_64
    libX11-common-1.6.0-2.2.16.amzn1.x86_64
    libX11-devel-1.6.0-2.2.16.amzn1.x86_64
    libX11-1.6.0-2.2.16.amzn1.x86_64