LibX11 Package Security Update Advisory (CVE-2023-43786, CVE-2023-43787)

Overview

 

An update has been made available to address a vulnerability in the libX11 package. users of affected versions are advised to update to the latest version.

 

Affected Products

 

versions of libX11 prior to 1.8.7

 

Resolved Vulnerabilities

 

doS vulnerability due to an infinite loop in the PutSubImage() function in libX11 (CVE-2023-43786)

arbitrary code execution vulnerability due to an integer overflow in the XCreateImage() function in libX11 (CVE-2023-43787)

 

Vulnerability Patches

 

vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

libX11 version 1.8.7

 

Referenced Sites

 

[1] cve-2024-2193

https://nvd.nist.gov/vuln/detail/CVE-2023-43786

[2] CVE-2023-43787 Detail

https://nvd.nist.gov/vuln/detail/CVE-2023-43787#range-10348725

[3] libX11 – Core X11 protocol client library

https://gitlab.freedesktop.org/xorg/lib/libx11