ALAS-2023-1895

Related Vulnerabilities: CVE-2023-43786  

A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition. (CVE-2023-43786)

ALAS-2023-1895


Amazon Linux 1 Security Advisory: ALAS-2023-1895
Advisory Release Date: 2023-11-29 23:18 Pacific
Advisory Updated Date: 2023-12-04 21:36 Pacific
Severity: Medium

Issue Overview:

A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition. (CVE-2023-43786)


Affected Packages:

libX11


Issue Correction:
Run yum update libX11 to update your system.

New Packages:
i686:
    libX11-debuginfo-1.6.0-2.2.17.amzn1.i686
    libX11-common-1.6.0-2.2.17.amzn1.i686
    libX11-devel-1.6.0-2.2.17.amzn1.i686
    libX11-1.6.0-2.2.17.amzn1.i686

src:
    libX11-1.6.0-2.2.17.amzn1.src

x86_64:
    libX11-devel-1.6.0-2.2.17.amzn1.x86_64
    libX11-1.6.0-2.2.17.amzn1.x86_64
    libX11-debuginfo-1.6.0-2.2.17.amzn1.x86_64
    libX11-common-1.6.0-2.2.17.amzn1.x86_64