安全公告详情

NS-SA-2026-0102

2026-09-07 18:00:00

简介

important: librabbitmq/xorg-x11-server security update

严重级别

important

主题

An update for librabbitmq/xorg-x11-server is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

librabbitmq:
xorg-x11-server:


Security Fix(es):
librabbitmq: A flaw was found in librabbitmq. This issue occurs because credentials can only be entered on the command line (for example, for amqp-publish or amqp-consume) and are visible to local attackers by listing a process and its arguments.(CVE-2023-35789)
librabbitmq: bugfix
xorg-x11-server: A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a buffer overflow condition via a specially crafted payload, leading to denial of service or local privilege escalation in distributions where the X.org server is run with root privileges.(CVE-2024-9632)
xorg-x11-server: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • librabbitmq
  • xorg-x11-server

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["librabbitmq-0.13.0-3.zncgsl7.2.x86_64.rpm","librabbitmq-doc-0.13.0-3.zncgsl7.2.noarch.rpm","librabbitmq-devel-0.13.0-3.zncgsl7.2.x86_64.rpm"],"source":"librabbitmq-0.13.0-3.zncgsl7.2.src.rpm"},{"binary":["xorg-x11-server-devel-1.20.14-13.zncgsl7.11.x86_64.rpm","xorg-x11-server-Xephyr-1.20.14-13.zncgsl7.11.x86_64.rpm","xorg-x11-server-Xorg-1.20.14-13.zncgsl7.11.x86_64.rpm","xorg-x11-server-common-1.20.14-13.zncgsl7.11.x86_64.rpm","xorg-x11-server-Xvfb-1.20.14-13.zncgsl7.11.x86_64.rpm","xorg-x11-server-Xnest-1.20.14-13.zncgsl7.11.x86_64.rpm","xorg-x11-server-source-1.20.14-13.zncgsl7.11.noarch.rpm","xorg-x11-server-Xdmx-1.20.14-13.zncgsl7.11.x86_64.rpm"],"source":"xorg-x11-server-1.20.14-13.zncgsl7.11.src.rpm"}]}]}

CVE

参考