FreshPorts - VuXML
This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2024-03-27 18:04:16 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
k68
These are the vulnerabilities relating to the commit you have selected:
VuXML ID | Description |
465db5b6-9c6d-11eb-8e8a-bc542f4bd1dd | xorg-server -- Input validation failures in X server XInput extension
X.Org server security reports for release 1.20.11:
- Fix XChangeFeedbackControl() request underflow
.
Discovery 2021-04-13 Entry 2021-04-13 xorg-server
< 1.20.11,1
xwayland
< 1.20.11,1
xwayland-devel
le 1.20.0.877
https://gitlab.freedesktop.org/xorg/xserver/-/tags/xorg-server-1.20.11
|
9fa7b139-c1e9-409e-bed0-006aadcf5845 | xorg-server -- Multiple security issues in X server extensions
The X.org project reports:
- CVE-2022-46340/ZDI-CAN-19265: X.Org Server XTestSwapFakeInput stack
overflow
The swap handler for the XTestFakeInput request of the XTest extension
may corrupt the stack if GenericEvents with lengths larger than 32 bytes
are sent through a the XTestFakeInput request.
This issue does not affect systems where client and server use the same
byte order.
- CVE-2022-46341/ZDI-CAN-19381: X.Org Server XIPassiveUngrab
out-of-bounds access
The handler for the XIPassiveUngrab request accesses out-of-bounds
memory when invoked with a high keycode or button code.
- CVE-2022-46342/ZDI-CAN-19400: X.Org Server XvdiSelectVideoNotify
use-after-free
The handler for the XvdiSelectVideoNotify request may write to memory
after it has been freed.
- CVE-2022-46343/ZDI-CAN-19404: X.Org Server ScreenSaverSetAttributes
use-after-free
The handler for the ScreenSaverSetAttributes request may write to memory
after it has been freed.
- CVE-2022-46344/ZDI-CAN-19405: X.Org Server XIChangeProperty
out-of-bounds access
The handler for the XIChangeProperty request has a length-validation
issues, resulting in out-of-bounds memory reads and potential
information disclosure.
- CVE-2022-4283/ZDI-CAN-19530: X.Org Server XkbGetKbdByName use-after-free
The XkbCopyNames function left a dangling pointer to freed memory,
resulting in out-of-bounds memory access on subsequent XkbGetKbdByName
requests.
Discovery 2022-12-14 Entry 2023-01-11 xorg-server
xephyr
xorg-vfbserver
< 21.1.5,1
xorg-nestserver
< 21.1.5,2
xwayland
< 22.1.6,1
xwayland-devel
< 21.0.99.1.319
https://lists.x.org/archives/xorg-announce/2022-December/003302.html
CVE-2022-46340
CVE-2022-46341
CVE-2022-46342
CVE-2022-46343
CVE-2022-46344
CVE-2022-4283
|