Wednesday, June 5, 2013

[USN-1862-1] libxrandr vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJRr4NmAAoJEGVp2FWnRL6T1McP/13oPPhGNQ1RFcR9x7/xGuuH
YgNhC7XjtS7/hZ6paPpNdMZwXLLCCm0hVkviHh00u1S1ixlNx+tUXIgj6/9cRGd/
Hkdf+SzYoAPWMy4jdQHMzv8PJ1DYBhfEO+uatP0KgWf9amDYCsKE2Bt1M79TU6Y1
tYzO95i4NYHSE2TeymHze9hJby0h21LYYkKSzBZ9WyBhS6dLatCBRD0IEJCGYmSI
qRFKZ9zpo08sLZR64961r/qYCT0qx6NtnrynAfaDxgMDbe+ep0T0rBKh/35Cu2bc
nmxkwW4kD+6eO/DOmgqnKqjsWMbX8pMB5eUQ1Pu9qzkOotr0wJVCNA3WmAzG5jxe
+NzTFdwWHWtLv4zhpr0C3jZgHu7AzonW+8eBMC8q1j4Yv8PfjWvb6lIjQRrLaKJC
HQGfIATkflAkFXxBUy4mnutv1o/JqjlgdUi+i/fDzzMW0MJZs3fJY3xKMkJvmG0M
td5i/VQ5LojX3dvkogen6LFMH9pWRc92tyGvLHaJs0vIKqdKAMgbNvB/eta51Nvb
cxXy00He1JxVKiwvZdqACSVhfb09O29ras6+JfAMhCzrI0HYO2CWv62g8jEa1q92
GD4p+x4W0vvsaG7RRjThTv6uY8ceP0bCs+rivLsxq0iGu6Tw0juIBtbxSghrPo08
qTKzWJNHwoqTusxcAtG+
=wtte
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1862-1
June 05, 2013

libxrandr, libxrandr-lts-quantal vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in libxrandr.

Software Description:
- libxrandr: X11 RandR extension library
- libxrandr-lts-quantal: X11 RandR extension library

Details:

Ilja van Sprundel discovered multiple security issues in various X.org
libraries and components. An attacker could use these issues to cause
applications to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
libxrandr2 2:1.4.0-1ubuntu1.1

Ubuntu 12.10:
libxrandr2 2:1.4.0-1ubuntu0.1

Ubuntu 12.04 LTS:
libxrandr-ltsq2 2:1.4.0-1~precise2
libxrandr2 2:1.3.2-2ubuntu0.2

After a standard system update you need to restart your session to make all
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1862-1
CVE-2013-1986

Package Information:
https://launchpad.net/ubuntu/+source/libxrandr/2:1.4.0-1ubuntu1.1
https://launchpad.net/ubuntu/+source/libxrandr/2:1.4.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libxrandr/2:1.3.2-2ubuntu0.2

https://launchpad.net/ubuntu/+source/libxrandr-lts-quantal/2:1.4.0-1~precise2

No comments:

Post a Comment