-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/
iQIcBAEBCgAGBQJRwzl8AAoJEGVp2FWnRL6TfQYP/1reDqHXApnpi5TN99TDBhW6
dn3ZBTTCcw1OPoE52XHzQq8qNiOpnuF65uB+8emjkrOQ6ijPKUbf3t8W2DwjgwQl
upO/SU7YYSknpyNX0MHr+k0eSN2seDB+iQ3a2u9clciT/0q68N18lEzAPzk6vDEo
w2FSPJ4PldySvfL32bbx2ojcD/nOJWpYKZ2Sg/k8GXT+RB3MiCb3QOi/ZPtatPtn
BlUBP2HLFJXPBs/miULhFVFmayiWplEWOgFtnrVrH9e+YAwyw1XmTK3UyTkOGQgJ
IF4Ub6HKLl5dl4xIa8DD0ie7TJX2FjxJO1fEDQu/QpATougm/rgCI1SoOgTg7cjG
3n+6yYEPLSllqFLgEqeRADh6oI4Rtqtqqc5J2m/3JEl77MYORJnZcZ/Vk1fCaFud
+0tb8PB/QvdABC3VOi8vteZozZkVdAmyxDsKbmS1p37AslUZV/RdS1s5nbWkaHJU
OnF8vLPXd/1ffrXjJO9BjsmlKv0WlSPgLO0V+cV43NGLmIXxCKehWV/a+pLNUAtO
40VIpibR06oVDhRzTQQeFuvc+NliLC2CoznDIFkULF/J6+B41ekpY90gFpNsEh+5
5BZ+D4G1iyAQVgSpQqMB/m08ZxmIuUXvAxZ2c3x4wPH8f7mfoUs4WRfJtTJKF72f
iB21AKxl9dJIvrAPtjKI
=HBjR
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1888-1
June 20, 2013
mesa, mesa-lts-quantal vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Mesa could be made to crash or run programs as your login if it received
specially crafted input.
Software Description:
- mesa: free implementation of the EGL API
- mesa-lts-quantal: free implementation of the EGL API
Details:
It was discovered that Mesa incorrectly handled certain memory
calculations. An attacker could use this flaw to cause an application to
crash, or possibly execute arbitrary code. (CVE-2013-1872)
Ilja van Sprundel discovered that Mesa incorrectly handled certain memory
calculations. An attacker could use this flaw to cause an application to
crash, or possibly execute arbitrary code. (CVE-2013-1993)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
libegl1-mesa 9.1.3-0ubuntu0.3
libgbm1 9.1.3-0ubuntu0.3
libgl1-mesa-dri 9.1.3-0ubuntu0.3
libgl1-mesa-glx 9.1.3-0ubuntu0.3
libglapi-mesa 9.1.3-0ubuntu0.3
libgles1-mesa 9.1.3-0ubuntu0.3
libgles2-mesa 9.1.3-0ubuntu0.3
libopenvg1-mesa 9.1.3-0ubuntu0.3
libosmesa6 9.1.3-0ubuntu0.3
libxatracker1 9.1.3-0ubuntu0.3
Ubuntu 12.10:
libegl1-mesa 9.0.3-0ubuntu0.2
libgbm1 9.0.3-0ubuntu0.2
libgl1-mesa-dri 9.0.3-0ubuntu0.2
libgl1-mesa-glx 9.0.3-0ubuntu0.2
libglapi-mesa 9.0.3-0ubuntu0.2
libgles1-mesa 9.0.3-0ubuntu0.2
libgles2-mesa 9.0.3-0ubuntu0.2
libopenvg1-mesa 9.0.3-0ubuntu0.2
libosmesa6 9.0.3-0ubuntu0.2
libxatracker1 9.0.3-0ubuntu0.2
Ubuntu 12.04 LTS:
libegl1-mesa 8.0.4-0ubuntu0.6
libegl1-mesa-lts-quantal 9.0.3-0ubuntu0.1~precise3
libgbm1 8.0.4-0ubuntu0.6
libgbm1-lts-quantal 9.0.3-0ubuntu0.1~precise3
libgl1-mesa-dri 8.0.4-0ubuntu0.6
libgl1-mesa-dri-lts-quantal 9.0.3-0ubuntu0.1~precise3
libgl1-mesa-glx 8.0.4-0ubuntu0.6
libgl1-mesa-glx-lts-quantal 9.0.3-0ubuntu0.1~precise3
libgl1-mesa-swx11 8.0.4-0ubuntu0.6
libglapi-mesa 8.0.4-0ubuntu0.6
libglapi-mesa-lts-quantal 9.0.3-0ubuntu0.1~precise3
libgles1-mesa 8.0.4-0ubuntu0.6
libgles1-mesa-lts-quantal 9.0.3-0ubuntu0.1~precise3
libgles2-mesa 8.0.4-0ubuntu0.6
libgles2-mesa-lts-quantal 9.0.3-0ubuntu0.1~precise3
libglu1-mesa 8.0.4-0ubuntu0.6
libopenvg1-mesa 8.0.4-0ubuntu0.6
libopenvg1-mesa-lts-quantal 9.0.3-0ubuntu0.1~precise3
libosmesa6 8.0.4-0ubuntu0.6
libxatracker1 8.0.4-0ubuntu0.6
libxatracker1-lts-quantal 9.0.3-0ubuntu0.1~precise3
After a standard system update you need to restart your session to make all
the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1888-1
CVE-2013-1872, CVE-2013-1993
Package Information:
https://launchpad.net/ubuntu/+source/mesa/9.1.3-0ubuntu0.3
https://launchpad.net/ubuntu/+source/mesa/9.0.3-0ubuntu0.2
https://launchpad.net/ubuntu/+source/mesa/8.0.4-0ubuntu0.6
https://launchpad.net/ubuntu/+source/mesa-lts-quantal/9.0.3-0ubuntu0.1~precise3
No comments:
Post a Comment