News: 0000827701

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

X.org security fixes address potential ASLR bypass, heap corruption

([Security] Jul 31, 2020 17:38 UTC (Fri) (coogle))


The X.Org project has announced two security advisories that impact Xserver and libX11. The [1]first advisory for X server is regarding uninitialized memory in AllocatePixmap() that could lead to [2]address space layout randomization bypass . [3]The second , impacting libX11, is a heap corruption caused by integer overflows and signed/unsigned comparisons.



[1] https://lwn.net/Articles/827704

[2] https://en.wikipedia.org/wiki/Address_space_layout_randomization

[3] https://lwn.net/Articles/827705

Good government never depends upon laws, but upon the personal qualities of
those who govern. The machinery of government is always subordinate to the
will of those who administer that machinery. The most important element of
government, therefore, is the method of choosing leaders.
-- Frank Herbert, "Children of Dune"