ALINUX2-SA-2022%3A0001
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2021-4008: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CVE-2021-4009: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CVE-2021-4010: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CVE-2021-4011: A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | xorg-x11-server |
Timeline
- Jan 4, 2022 CVE Published
- Jan 4, 2022 CVE Updated
References
- ALINUX2-SA-2022:0001: xorg-x11-server security update (Important) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4010 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4011 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4008 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4009 advisory