Files
poky/meta/recipes-graphics
Ross Burton 411184bfaa xserver-xorg: fix CVE-2018-14665
Incorrect command-line parameter validation in the Xorg X server can lead to
privilege elevation and/or arbitrary files overwrite, when the X server is
running with elevated privileges (ie when Xorg is installed with the setuid bit
set and started by a non-root user). The -modulepath argument can be used to
specify an insecure path to modules that are going to be loaded in the X server,
allowing to execute unprivileged code in the privileged process. The -logfile
argument can be used to overwrite arbitrary files in the file system, due to
incorrect checks in the parsing of the option.

(From OE-Core rev: 14b5854d50c38e94fc0d1ce6af36698fc69f52b4)

Signed-off-by: Ross Burton <ross.burton@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2018-11-01 13:27:26 +00:00
..
2016-06-15 18:05:23 +01:00
2016-12-20 15:22:16 +00:00
2018-09-11 09:05:35 +01:00
2018-08-23 07:50:00 +01:00
2017-11-09 12:33:17 +00:00
2018-09-11 10:46:17 +01:00
2016-07-10 14:12:17 +01:00
2018-06-27 13:55:21 +01:00
2018-07-18 10:18:42 +01:00
2018-10-18 23:26:35 +01:00
2018-10-04 14:21:41 +01:00
2018-10-08 14:13:54 +01:00
2018-06-21 09:34:40 +01:00
2018-10-09 12:02:00 +01:00
2018-07-30 12:44:35 +01:00