ELA-255-1 libx11 security update

Heap corruption in the X input method

2020-08-03
Packagelibx11
Version2:1.6.2-3+deb8u3
Related CVEs CVE-2020-14344


The X Input Method (XIM) client implementation in libX11 has some integer overflows and signed/unsigned comparison issues that can lead to heap corruption when handling malformed messages from an input method.



For Debian 8 jessie, these problems have been fixed in version 2:1.6.2-3+deb8u3.

We recommend that you upgrade your libx11 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.