openSUSE Security Update: Security update for xorg-x11-server ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:1610-1 Rating: moderate References: #1025029 #1025035 #1025084 Cross-References: CVE-2017-2624 Affected Products: openSUSE Leap 42.2 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for xorg-x11-server fixes the following security issues: - CVE-2017-2624: Prevent timing attack against MIT cookie. (boo#1025029) - Use arc4random to generate cookies with more randomness. (boo#1025084) - Remove unused function with use-after-free issue. (boo#1025035) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-710=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (i586 x86_64): xorg-x11-server-7.6_1.18.3-12.15.2 xorg-x11-server-debuginfo-7.6_1.18.3-12.15.2 xorg-x11-server-debugsource-7.6_1.18.3-12.15.2 xorg-x11-server-extra-7.6_1.18.3-12.15.2 xorg-x11-server-extra-debuginfo-7.6_1.18.3-12.15.2 xorg-x11-server-sdk-7.6_1.18.3-12.15.2 xorg-x11-server-source-7.6_1.18.3-12.15.2 References: https://www.suse.com/security/cve/CVE-2017-2624.html https://bugzilla.suse.com/1025029 https://bugzilla.suse.com/1025035 https://bugzilla.suse.com/1025084