Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 734974 (CVE-2020-14344)

Summary: <x11-libs/libX11-1.6.10: Multiple vulnerabilities (CVE-2020-14344)
Product: Gentoo Security Reporter: Sam James <sam>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: bertrand, tamiko, x11
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://lists.x.org/archives/xorg-devel/2020-July/058597.html
See Also: https://bugs.gentoo.org/show_bug.cgi?id=734976
Whiteboard: A2 [glsa+ cve]
Package list:
x11-libs/libX11-1.6.11
Runtime testing required: ---
Bug Depends on: 735596, 738984    
Bug Blocks:    

Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-31 16:55:44 UTC
Description:
"The X Input Method (XIM) client implementation in libX11 has some
integer overflows and signed/unsigned comparison issues that can lead
to heap corruption when handling malformed messages from an input
method."
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-31 17:00:10 UTC
"libX11 1.6.10 will be released shortly and will include those patches."

Bump when ready, thanks!
Comment 2 Larry the Git Cow gentoo-dev 2020-07-31 19:42:27 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a8d6ca4533b82ae5ba111fa3306fde5503e458b6

commit a8d6ca4533b82ae5ba111fa3306fde5503e458b6
Author:     Matt Turner <mattst88@gentoo.org>
AuthorDate: 2020-07-31 19:38:49 +0000
Commit:     Matt Turner <mattst88@gentoo.org>
CommitDate: 2020-07-31 19:42:14 +0000

    x11-libs/libX11: Version bump to 1.6.10
    
    Bug: https://bugs.gentoo.org/734974
    Signed-off-by: Matt Turner <mattst88@gentoo.org>

 x11-libs/libX11/Manifest             |  1 +
 x11-libs/libX11/libX11-1.6.10.ebuild | 30 ++++++++++++++++++++++++++++++
 2 files changed, 31 insertions(+)
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-07-31 19:51:46 UTC
Thanks. Tell us when ready to stable.
Comment 4 NATTkA bot gentoo-dev 2020-07-31 19:52:25 UTC
Unable to check for sanity:

> no match for package: dev-libs/libX11-1.6.10
Comment 5 Matt Turner gentoo-dev 2020-08-03 15:31:33 UTC
1.6.11 will be released this week with a fix for the blocking bug. We'll stabilize that instead.
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-06 19:09:22 UTC
(In reply to Matt Turner from comment #5)
> 1.6.11 will be released this week with a fix for the blocking bug. We'll
> stabilize that instead.

Thanks.
Comment 7 Agostino Sarubbo gentoo-dev 2020-08-10 14:34:04 UTC
amd64 stable
Comment 8 Sergei Trofimovich (RETIRED) gentoo-dev 2020-08-11 07:09:23 UTC
sparc stable
Comment 9 Sergei Trofimovich (RETIRED) gentoo-dev 2020-08-11 07:12:34 UTC
hppa stable
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-11 08:19:17 UTC
arm done
Comment 11 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-11 08:19:55 UTC
arm64 done
Comment 12 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-11 09:07:34 UTC
x86 done
Comment 13 Agostino Sarubbo gentoo-dev 2020-08-11 14:14:00 UTC
s390 stable
Comment 14 NATTkA bot gentoo-dev 2020-08-25 17:00:50 UTC
Resetting sanity check; keywords are not fully specified and arches are not CC-ed.
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2020-08-27 23:57:21 UTC
This issue was resolved and addressed in
 GLSA 202008-18 at https://security.gentoo.org/glsa/202008-18
by GLSA coordinator Sam James (sam_c).