CVE-2018-14665 : Xorg X Server Vulnerabilities

Post Reply
Message
Author
User avatar
Protokol
Posts: 18
Joined: Fri Apr 13, 2018 10:46 am

CVE-2018-14665 : Xorg X Server Vulnerabilities

#1 Post by Protokol »

hello,

a "new" security vulnerability found on linux systems, security patch on the way ?

see https://www.securepatterns.com/2018/10/ ... erver.html
Hewlett-Packard Compaq Presario CQ71 Notebook
Kernel: 4.19.0-12-amd64 x86_64
Desktop: MX-19.2_x64 patito feo May 31 2020
Graphics: Intel Mobile 4 Series Integrated Graphics
Ram : 4GB

User avatar
Richard
Posts: 1577
Joined: Fri Dec 12, 2008 10:31 am

Re: CVE-2018-14665 : Xorg X Server Vulnerabilities

#2 Post by Richard »

Well, perhaps.
Although it was only reported yesterday I imagine that work has already begun.
Thinkpad T430 & Dell Latitude E7450, both with MX-21.3.1
kernal 5.10.0-26-amd64 x86_64; Xfce-4.18.0; 8 GB RAM
Intel Core i5-3380M, Graphics, Audio, Video; & SSDs.

User avatar
timkb4cq
Developer
Posts: 3203
Joined: Wed Jul 12, 2006 4:05 pm

Re: CVE-2018-14665 : Xorg X Server Vulnerabilities

#3 Post by timkb4cq »

https://security-tracker.debian.org/tra ... 2018-14665
As you can see, it's already patched in stretch (MX-17) and jessie (MX-15/16)
HP Pavillion TP01, AMD Ryzen 3 5300G (quad core), Crucial 500GB SSD, Toshiba 6TB 7200rpm
Dell Inspiron 15, AMD Ryzen 7 2700u (quad core). Sabrent 500GB nvme, Seagate 1TB

User avatar
ChrisUK
Qualified MX Guide
Posts: 299
Joined: Tue Dec 12, 2017 1:04 pm

Re: CVE-2018-14665 : Xorg X Server Vulnerabilities

#4 Post by ChrisUK »

Auto updated (MX Upater) this morning at 05:51 (UK time, about 9 hours ago)

Code: Select all

2018-10-26  05:51:41  upgrade  xserver-xorg-core                       amd64  2:1.19.2-1+deb9u2               2:1.19.2-1+deb9u4
2018-10-26  05:51:40  upgrade  xserver-xorg-legacy                     amd64  2:1.19.2-1+deb9u2               2:1.19.2-1+deb9u4
2018-10-26  05:51:39  upgrade  xserver-common                          all    2:1.19.2-1+deb9u2               2:1.19.2-1+deb9u4
2018-10-26  05:51:32  upgrade  openjdk-8-jre-headless                  amd64  8u181-b13-1~deb9u1              8u181-b13-2~deb9u1
2018-10-26  05:51:31  upgrade  openjdk-8-jre                           amd64  8u181-b13-1~deb9u1              8u181-b13-2~deb9u1
Chris

MX 18 MX 19 - Manjaro

User avatar
Protokol
Posts: 18
Joined: Fri Apr 13, 2018 10:46 am

Re: CVE-2018-14665 : Xorg X Server Vulnerabilities

#5 Post by Protokol »

ok, I didn't even noticed the update, you're right!
Hewlett-Packard Compaq Presario CQ71 Notebook
Kernel: 4.19.0-12-amd64 x86_64
Desktop: MX-19.2_x64 patito feo May 31 2020
Graphics: Intel Mobile 4 Series Integrated Graphics
Ram : 4GB

User avatar
Stevo
Developer
Posts: 12837
Joined: Fri Dec 15, 2006 8:07 pm

Re: CVE-2018-14665 : Xorg X Server Vulnerabilities

#6 Post by Stevo »

Since we decided to push openjdk-8 as the default Java in MX 15/16, that means we need to backport the Stretch security update...working on it. That's one of the ones I can't do the easy way in pbuilder, I think.

Post Reply

Return to “General”