<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">xorg-x11-server-1.20.13-1.2 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:11525</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-17T21:45:33Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-17T21:45:33Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-17T21:45:33Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">xorg-x11-server-1.20.13-1.2 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the xorg-x11-server-1.20.13-1.2 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-11525</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL/>
      <Description>E-Mail link for openSUSE-SU-2024:11525</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-6101/</URL>
      <Description>SUSE CVE CVE-2006-6101 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-6102/</URL>
      <Description>SUSE CVE CVE-2006-6102 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2006-6103/</URL>
      <Description>SUSE CVE CVE-2006-6103 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2007-1003/</URL>
      <Description>SUSE CVE CVE-2007-1003 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2007-5760/</URL>
      <Description>SUSE CVE CVE-2007-5760 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2007-6427/</URL>
      <Description>SUSE CVE CVE-2007-6427 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2007-6428/</URL>
      <Description>SUSE CVE CVE-2007-6428 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2007-6429/</URL>
      <Description>SUSE CVE CVE-2007-6429 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2008-0006/</URL>
      <Description>SUSE CVE CVE-2008-0006 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2008-1377/</URL>
      <Description>SUSE CVE CVE-2008-1377 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2008-1379/</URL>
      <Description>SUSE CVE CVE-2008-1379 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2008-2360/</URL>
      <Description>SUSE CVE CVE-2008-2360 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2008-2361/</URL>
      <Description>SUSE CVE CVE-2008-2361 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2008-2362/</URL>
      <Description>SUSE CVE CVE-2008-2362 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-10971/</URL>
      <Description>SUSE CVE CVE-2017-10971 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-12176/</URL>
      <Description>SUSE CVE CVE-2017-12176 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-12187/</URL>
      <Description>SUSE CVE CVE-2017-12187 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-13721/</URL>
      <Description>SUSE CVE CVE-2017-13721 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-2624/</URL>
      <Description>SUSE CVE CVE-2017-2624 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-14665/</URL>
      <Description>SUSE CVE CVE-2018-14665 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-14345/</URL>
      <Description>SUSE CVE CVE-2020-14345 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-14346/</URL>
      <Description>SUSE CVE CVE-2020-14346 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-14347/</URL>
      <Description>SUSE CVE CVE-2020-14347 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-14360/</URL>
      <Description>SUSE CVE CVE-2020-14360 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-14361/</URL>
      <Description>SUSE CVE CVE-2020-14361 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-14362/</URL>
      <Description>SUSE CVE CVE-2020-14362 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25712/</URL>
      <Description>SUSE CVE CVE-2020-25712 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3472/</URL>
      <Description>SUSE CVE CVE-2021-3472 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="xorg-x11-server-1.20.13-1.2">
      <FullProductName ProductID="xorg-x11-server-1.20.13-1.2">xorg-x11-server-1.20.13-1.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xorg-x11-server-Xvfb-1.20.13-1.2">
      <FullProductName ProductID="xorg-x11-server-Xvfb-1.20.13-1.2">xorg-x11-server-Xvfb-1.20.13-1.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xorg-x11-server-extra-1.20.13-1.2">
      <FullProductName ProductID="xorg-x11-server-extra-1.20.13-1.2">xorg-x11-server-extra-1.20.13-1.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xorg-x11-server-sdk-1.20.13-1.2">
      <FullProductName ProductID="xorg-x11-server-sdk-1.20.13-1.2">xorg-x11-server-sdk-1.20.13-1.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xorg-x11-server-source-1.20.13-1.2">
      <FullProductName ProductID="xorg-x11-server-source-1.20.13-1.2">xorg-x11-server-source-1.20.13-1.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xorg-x11-server-wrapper-1.20.13-1.2">
      <FullProductName ProductID="xorg-x11-server-wrapper-1.20.13-1.2">xorg-x11-server-wrapper-1.20.13-1.2</FullProductName>
    </Branch>
    <Relationship ProductReference="xorg-x11-server-1.20.13-1.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2">xorg-x11-server-1.20.13-1.2 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="xorg-x11-server-Xvfb-1.20.13-1.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2">xorg-x11-server-Xvfb-1.20.13-1.2 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="xorg-x11-server-extra-1.20.13-1.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2">xorg-x11-server-extra-1.20.13-1.2 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="xorg-x11-server-sdk-1.20.13-1.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2">xorg-x11-server-sdk-1.20.13-1.2 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="xorg-x11-server-source-1.20.13-1.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2">xorg-x11-server-source-1.20.13-1.2 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="xorg-x11-server-wrapper-1.20.13-1.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2">xorg-x11-server-wrapper-1.20.13-1.2 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph management data structures.</Note>
    </Notes>
    <CVE>CVE-2006-6101</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-6101.html</URL>
        <Description>CVE-2006-6101</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/225972</URL>
        <Description>SUSE Bug 225972</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</Note>
    </Notes>
    <CVE>CVE-2006-6102</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-6102.html</URL>
        <Description>CVE-2006-6102</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/225974</URL>
        <Description>SUSE Bug 225974</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</Note>
    </Notes>
    <CVE>CVE-2006-6103</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2006-6103.html</URL>
        <Description>CVE-2006-6103</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/225975</URL>
        <Description>SUSE Bug 225975</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</Note>
    </Notes>
    <CVE>CVE-2007-1003</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2007-1003.html</URL>
        <Description>CVE-2007-1003</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/243978</URL>
        <Description>SUSE Bug 243978</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/261141</URL>
        <Description>SUSE Bug 261141</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index.</Note>
    </Notes>
    <CVE>CVE-2007-5760</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2007-5760.html</URL>
        <Description>CVE-2007-5760</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/345496</URL>
        <Description>SUSE Bug 345496</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.</Note>
    </Notes>
    <CVE>CVE-2007-6427</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2007-6427.html</URL>
        <Description>CVE-2007-6427</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/345127</URL>
        <Description>SUSE Bug 345127</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.</Note>
    </Notes>
    <CVE>CVE-2007-6428</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2007-6428.html</URL>
        <Description>CVE-2007-6428</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/345128</URL>
        <Description>SUSE Bug 345128</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.</Note>
    </Notes>
    <CVE>CVE-2007-6429</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2007-6429.html</URL>
        <Description>CVE-2007-6429</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/345130</URL>
        <Description>SUSE Bug 345130</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/345131</URL>
        <Description>SUSE Bug 345131</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.</Note>
    </Notes>
    <CVE>CVE-2008-0006</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2008-0006.html</URL>
        <Description>CVE-2008-0006</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/348296</URL>
        <Description>SUSE Bug 348296</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.</Note>
    </Notes>
    <CVE>CVE-2008-1377</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2008-1377.html</URL>
        <Description>CVE-2008-1377</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/374318</URL>
        <Description>SUSE Bug 374318</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/374323</URL>
        <Description>SUSE Bug 374323</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.</Note>
    </Notes>
    <CVE>CVE-2008-1379</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2008-1379.html</URL>
        <Description>CVE-2008-1379</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/374318</URL>
        <Description>SUSE Bug 374318</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/374320</URL>
        <Description>SUSE Bug 374320</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based buffer overflow.</Note>
    </Notes>
    <CVE>CVE-2008-2360</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2008-2360.html</URL>
        <Description>CVE-2008-2360</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/374321</URL>
        <Description>SUSE Bug 374321</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.</Note>
    </Notes>
    <CVE>CVE-2008-2361</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2008-2361.html</URL>
        <Description>CVE-2008-2361</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/374321</URL>
        <Description>SUSE Bug 374321</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient request with an invalid field specifying the number of bytes to swap in the request data, which triggers heap memory corruption.</Note>
    </Notes>
    <CVE>CVE-2008-2362</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2008-2362.html</URL>
        <Description>CVE-2008-2362</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/374321</URL>
        <Description>SUSE Bug 374321</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.</Note>
    </Notes>
    <CVE>CVE-2017-10971</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-10971.html</URL>
        <Description>CVE-2017-10971</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1035283</URL>
        <Description>SUSE Bug 1035283</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1047730</URL>
        <Description>SUSE Bug 1047730</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.</Note>
    </Notes>
    <CVE>CVE-2017-12176</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.6</BaseScore>
        <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-12176.html</URL>
        <Description>CVE-2017-12176</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1063041</URL>
        <Description>SUSE Bug 1063041</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.</Note>
    </Notes>
    <CVE>CVE-2017-12187</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.6</BaseScore>
        <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-12187.html</URL>
        <Description>CVE-2017-12187</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1063034</URL>
        <Description>SUSE Bug 1063034</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other X clients in the same session.</Note>
    </Notes>
    <CVE>CVE-2017-13721</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.7</BaseScore>
        <Vector>AV:L/AC:L/Au:S/C:P/I:P/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-13721.html</URL>
        <Description>CVE-2017-13721</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1051150</URL>
        <Description>SUSE Bug 1051150</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1052984</URL>
        <Description>SUSE Bug 1052984</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.</Note>
    </Notes>
    <CVE>CVE-2017-2624</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:L/AC:H/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-2624.html</URL>
        <Description>CVE-2017-2624</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1025029</URL>
        <Description>SUSE Bug 1025029</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1025639</URL>
        <Description>SUSE Bug 1025639</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1035283</URL>
        <Description>SUSE Bug 1035283</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.</Note>
    </Notes>
    <CVE>CVE-2018-14665</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-14665.html</URL>
        <Description>CVE-2018-14665</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1111697</URL>
        <Description>SUSE Bug 1111697</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1112020</URL>
        <Description>SUSE Bug 1112020</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2020-14345</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-14345.html</URL>
        <Description>CVE-2020-14345</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174635</URL>
        <Description>SUSE Bug 1174635</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174638</URL>
        <Description>SUSE Bug 1174638</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174908</URL>
        <Description>SUSE Bug 1174908</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174910</URL>
        <Description>SUSE Bug 1174910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174913</URL>
        <Description>SUSE Bug 1174913</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177596</URL>
        <Description>SUSE Bug 1177596</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181067</URL>
        <Description>SUSE Bug 1181067</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2020-14346</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-14346.html</URL>
        <Description>CVE-2020-14346</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174635</URL>
        <Description>SUSE Bug 1174635</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174638</URL>
        <Description>SUSE Bug 1174638</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174910</URL>
        <Description>SUSE Bug 1174910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174913</URL>
        <Description>SUSE Bug 1174913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could result in possible ASLR bypass. Xorg-server before version 1.20.9 is vulnerable.</Note>
    </Notes>
    <CVE>CVE-2020-14347</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-14347.html</URL>
        <Description>CVE-2020-14347</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174633</URL>
        <Description>SUSE Bug 1174633</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2020-14360</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-14360.html</URL>
        <Description>CVE-2020-14360</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174908</URL>
        <Description>SUSE Bug 1174908</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177596</URL>
        <Description>SUSE Bug 1177596</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2020-14361</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-14361.html</URL>
        <Description>CVE-2020-14361</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174635</URL>
        <Description>SUSE Bug 1174635</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174638</URL>
        <Description>SUSE Bug 1174638</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174910</URL>
        <Description>SUSE Bug 1174910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174913</URL>
        <Description>SUSE Bug 1174913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2020-14362</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-14362.html</URL>
        <Description>CVE-2020-14362</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174635</URL>
        <Description>SUSE Bug 1174635</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174638</URL>
        <Description>SUSE Bug 1174638</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174910</URL>
        <Description>SUSE Bug 1174910</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174913</URL>
        <Description>SUSE Bug 1174913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2020-25712</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25712.html</URL>
        <Description>CVE-2020-25712</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1174908</URL>
        <Description>SUSE Bug 1174908</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177596</URL>
        <Description>SUSE Bug 1177596</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in xorg-x11-server in versions before 1.20.11. An integer underflow can occur in xserver which can lead to a local privilege escalation. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2021-3472</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-Xvfb-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-extra-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-sdk-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-source-1.20.13-1.2</ProductID>
        <ProductID>openSUSE Tumbleweed:xorg-x11-server-wrapper-1.20.13-1.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3472.html</URL>
        <Description>CVE-2021-3472</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180128</URL>
        <Description>SUSE Bug 1180128</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
