ALAS-2014-406


Amazon Linux AMI Security Advisory: ALAS-2014-406
Advisory Release Date: 2014-09-19 12:05 Pacific
Severity: Medium
References: CVE-2013-2063 

Issue Overview:

Integer overflow in X.org libXtst 1.2.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XRecordGetContext function.


Affected Packages:

libXtst


Issue Correction:
Run yum update libXtst to update your system.

New Packages:
i686:
    libXtst-debuginfo-1.2.1-2.8.amzn1.i686
    libXtst-1.2.1-2.8.amzn1.i686
    libXtst-devel-1.2.1-2.8.amzn1.i686

src:
    libXtst-1.2.1-2.8.amzn1.src

x86_64:
    libXtst-1.2.1-2.8.amzn1.x86_64
    libXtst-debuginfo-1.2.1-2.8.amzn1.x86_64
    libXtst-devel-1.2.1-2.8.amzn1.x86_64