ELA-433-1 libx11 security update

protocol command injection

2021-05-24
Packagelibx11
Version2:1.6.2-3+deb8u5
Related CVEs CVE-2021-31535

Roman Fiedler found that libX11, the X11 protocol client library, was vulnerable to protocol command injection due to insufficient validation of arguments to some functions.

For Debian 8 jessie, these problems have been fixed in version 2:1.6.2-3+deb8u5.

We recommend that you upgrade your libx11 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/