Login
Newsletter
Werbung

Sicherheit: Pufferüberlauf in libXfont
Aktuelle Meldungen Distributionen
Name: Pufferüberlauf in libXfont
ID: USN-1191-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Mo, 15. August 2011, 15:40
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2895
Applikationen: X11

Originalnachricht


--===============7548528876584586198==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature"; boundary="=-3wSjruC4pJpm/SPCV8Ro"


--=-3wSjruC4pJpm/SPCV8Ro
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1191-1
August 15, 2011

libxfont vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

libXfont could be made to run programs as an administrator if it opened a
specially crafted file.

Software Description:
- libxfont: X11 font rasterisation library

Details:

Tomas Hoger discovered that libXfont incorrectly handled certain malformed
compressed fonts. An attacker could use a specially crafted font file to
cause libXfont to crash, or possibly execute arbitrary code in order to
gain privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
libxfont1 1:1.4.3-2ubuntu0.1

Ubuntu 10.10:
libxfont1 1:1.4.2-1ubuntu0.1

Ubuntu 10.04 LTS:
libxfont1 1:1.4.1-1ubuntu0.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1191-1
CVE-2011-2895

Package Information:
https://launchpad.net/ubuntu/+source/libxfont/1:1.4.3-2ubuntu0.1
https://launchpad.net/ubuntu/+source/libxfont/1:1.4.2-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libxfont/1:1.4.1-1ubuntu0.1



--ÓwSjruC4pJpm/SPCV8Ro
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJOSR9yAAoJEGVp2FWnRL6T/RAP/R2X2saSGoRKLf3kVPTiNNnW
TE4HkLgSz/ihzKyxsxFqwZLfHt2g1RUy1kcLBtfBu6aUsxs4bWytaniOklIcq0qx
KCPHXJkjYyy4aLtki5Q/grMacPTh8n1gIBau3U/n87uRcCCWy7I6YuaqJ0CSr4nc
M15jX+gi/pRipr57bFQ2Dv5ecXC2QOFZfDM5siG22xfVLVJ+iP2YmhUu8pt7x2nt
Z7qS9CGr1ra0O2onjaM97wX3/jrgTm0fbVNKLk0+LtLfBXG5ZrpVmEJim+9EYhR8
rV2ngmSFpp5JET7otZKIzemJ7o2tURM3tLrrwqLnNJUrWxARKeyS/fbSNVE09Vad
j3hF/r/rMByF9Tz7MfMb1Stp/oGItm6TlSIMj4vudsX7OqHSSNT141rMmuSJLnBG
2ReI8tnKjrO7S3hMOQmabyl//HO5rgSHWWO3KC6gLWheOETsJqymwa3q++P69Ny8
wzAjVDU/sx/0/nV1jl6lCe2sHmweFujA0FWflxyti9jMIJA8RheKvvGbQpXmXzaI
WM/6qS6VkptKpXWmhUaoWRcDmnPgc1tcndyPJWgJJFjPGFdCVAD9iF4KT0FXvpCY
bz0r7YN88iSQ8GyAfqCAt599k0F/5pudKoY4oxxEJVer+ENlUiucndlpqE4QWjnf
g1ZaV3RHUc1hvHsi/mxN
=nDN5
-----END PGP SIGNATURE-----

--=-3wSjruC4pJpm/SPCV8Ro--



--===============7548528876584586198==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============7548528876584586198==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung