CVE-2021-4008 - log back

CVE-2021-4008 edited at 14 Dec 2021 19:39:01
Description
- A security issue has been found in X.Org before version 21.1.2. The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.
+ A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.
References
https://lists.x.org/archives/xorg-announce/2021-December/003122.html
+ https://lists.x.org/archives/xorg-announce/2021-December/003123.html
https://gitlab.freedesktop.org/xorg/xserver/-/commit/ebce7e2d80e7c80e1dda60f2f0bc886f1106ba60
CVE-2021-4008 edited at 14 Dec 2021 13:57:18
Severity
- Medium
+ High
CVE-2021-4008 edited at 14 Dec 2021 13:53:34
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ A security issue has been found in X.Org before version 21.1.2. The handler for the CompositeGlyphs request of the Render extension does not properly validate the request length leading to out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.
References
+ https://lists.x.org/archives/xorg-announce/2021-December/003122.html
+ https://gitlab.freedesktop.org/xorg/xserver/-/commit/ebce7e2d80e7c80e1dda60f2f0bc886f1106ba60
Notes
CVE-2021-4008 created at 14 Dec 2021 13:50:53