SB2015050505 - Amazon Linux AMI update for xorg-x11-server
Published: May 5, 2015
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2015-0255)
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.
Remediation
Install update from vendor's website.