ALAS2-2023-2296

Related Vulnerabilities: CVE-2023-43785   CVE-2023-43787  

libX11: out-of-bounds memory access in _XkbReadKeySyms() (CVE-2023-43785) libX11: integer overflow in XCreateImage() leading to a heap overflow. (CVE-2023-43787)

ALAS2-2023-2296


Amazon Linux 2 Security Advisory: ALAS-2023-2296
Advisory Release Date: 2023-10-12 15:09 Pacific
Advisory Updated Date: 2023-10-19 23:40 Pacific
Severity: Medium

Issue Overview:

libX11: out-of-bounds memory access in _XkbReadKeySyms() (CVE-2023-43785)

libX11: integer overflow in XCreateImage() leading to a heap overflow. (CVE-2023-43787)


Affected Packages:

libX11


Issue Correction:
Run yum update libX11 to update your system.

New Packages:
aarch64:
    libX11-1.6.7-3.amzn2.0.4.aarch64
    libX11-devel-1.6.7-3.amzn2.0.4.aarch64
    libX11-debuginfo-1.6.7-3.amzn2.0.4.aarch64

i686:
    libX11-1.6.7-3.amzn2.0.4.i686
    libX11-devel-1.6.7-3.amzn2.0.4.i686
    libX11-debuginfo-1.6.7-3.amzn2.0.4.i686

noarch:
    libX11-common-1.6.7-3.amzn2.0.4.noarch

src:
    libX11-1.6.7-3.amzn2.0.4.src

x86_64:
    libX11-1.6.7-3.amzn2.0.4.x86_64
    libX11-devel-1.6.7-3.amzn2.0.4.x86_64
    libX11-debuginfo-1.6.7-3.amzn2.0.4.x86_64