CVE-2021-4011 - log back

CVE-2021-4011 edited at 14 Dec 2021 19:39:57
Description
- A security issue has been found in X.Org before version 21.1.2. The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to an out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.
+ A security issue has been found in X.Org before version 21.1.2 and Xwayland before version 21.1.4. The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to an out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.
References
https://lists.x.org/archives/xorg-announce/2021-December/003122.html
+ https://lists.x.org/archives/xorg-announce/2021-December/003123.html
https://gitlab.freedesktop.org/xorg/xserver/-/commit/e56f61c79fc3cee26d83cda0f84ae56d5979f768
CVE-2021-4011 edited at 14 Dec 2021 13:57:39
Severity
- Medium
+ High
References
https://lists.x.org/archives/xorg-announce/2021-December/003122.html
https://gitlab.freedesktop.org/xorg/xserver/-/commit/e56f61c79fc3cee26d83cda0f84ae56d5979f768
Notes
CVE-2021-4011 edited at 14 Dec 2021 13:55:29
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ A security issue has been found in X.Org before version 21.1.2. The handlers for the RecordCreateContext and RecordRegisterClients requests of the Record extension do not properly validate the request length leading to an out of bounds memory write. This can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for SSH X forwarding sessions.
References
+ https://lists.x.org/archives/xorg-announce/2021-December/003122.html
+ https://gitlab.freedesktop.org/xorg/xserver/-/commit/e56f61c79fc3cee26d83cda0f84ae56d5979f768
CVE-2021-4011 created at 14 Dec 2021 13:50:53