ASA-201708-11 generated external raw

[ASA-201708-11] xorg-server: multiple issues
Arch Linux Security Advisory ASA-201708-11 ========================================== Severity: High Date : 2017-08-14 CVE-ID : CVE-2017-10971 CVE-2017-10972 Package : xorg-server Type : multiple issues Remote : Yes Link : Summary ======= The package xorg-server before version 1.19.3-3 is vulnerable to multiple issues including arbitrary code execution and information disclosure. Resolution ========== Upgrade to 1.19.3-3. # pacman -Syu "xorg-server>=1.19.3-3" The problems have been fixed upstream but no release is available yet. Workaround ========== None. Description =========== - CVE-2017-10971 (arbitrary code execution) In the X.Org X server on v.1.19.3, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events. - CVE-2017-10972 (information disclosure) Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server on v1.19.3 and before allowed authenticated malicious users to access potentially privileged data from the X server. Impact ====== A remote attacker can access sensitive information or execute arbitrary code on the affected host. References ==========