Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1623250 - (CVE-2018-14599) CVE-2018-14599 libX11: off-by-one error in XListExtensions in ListExt.c
CVE-2018-14599 libX11: off-by-one error in XListExtensions in ListExt.c
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180821,repor...
: Security
Depends On: 1623251 1623252 1624787
Blocks: 1623253
  Show dependency treegraph
 
Reported: 2018-08-28 16:18 EDT by Laura Pardo
Modified: 2018-09-19 08:39 EDT (History)
22 users (show)

See Also:
Fixed In Version: libX11 1.6.6
Doc Type: If docs needed, set a value
Doc Text:
An off-by-one error has been discovered in libX11 in functions XGetFontPath(), XListExtensions(), and XListFonts(). An attacker who can either configure a malicious X server or modify the data coming from one could use this flaw to make the program crash or have other unspecified effects, caused by the memory corruption.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Laura Pardo 2018-08-28 16:18:13 EDT
An issue was discovered in libX11 through 1.6.5. Functions GetFPath.c:XGetFontPath, ListExt.c:XListExtensions and FontNames.c:XListFonts are vulnerable to an off-by-one error when parsing list of strings returned by malicious server responses, leading to DoS.


References:
http://www.openwall.com/lists/oss-security/2018/08/21/6
https://lists.x.org/archives/xorg-announce/2018-August/002916.html

Upstream Patch:
https://cgit.freedesktop.org/xorg/lib/libX11/commit/?id=b469da1430cdcee06e31c6251b83aede072a1ff0
Comment 1 Laura Pardo 2018-08-28 16:18:49 EDT
Created libX11 tracking bugs for this issue:

Affects: fedora-all [bug 1623251]
Comment 5 Riccardo Schirone 2018-09-03 05:51:33 EDT
Statement:

This issue did not affect the versions of libX11 as shipped with Red Hat Enterprise Linux 5 as they did not include the vulnerable code.

Note You need to log in before you can comment on or make changes to this bug.