Red Hat Bugzilla – Bug 1623250
CVE-2018-14599 libX11: off-by-one error in XListExtensions in ListExt.c
Last modified: 2018-09-19 08:39:04 EDT
An issue was discovered in libX11 through 1.6.5. Functions GetFPath.c:XGetFontPath, ListExt.c:XListExtensions and FontNames.c:XListFonts are vulnerable to an off-by-one error when parsing list of strings returned by malicious server responses, leading to DoS. References: http://www.openwall.com/lists/oss-security/2018/08/21/6 https://lists.x.org/archives/xorg-announce/2018-August/002916.html Upstream Patch: https://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=b469da1430cdcee06e31c6251b83aede072a1ff0
Created libX11 tracking bugs for this issue: Affects: fedora-all [bug 1623251]
Statement: This issue did not affect the versions of libX11 as shipped with Red Hat Enterprise Linux 5 as they did not include the vulnerable code.