Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in libx11 (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in libx11 (Aktualisierung)
ID: USN-4966-2
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 ESM, Ubuntu 16.04 ESM
Datum: Di, 25. Mai 2021, 21:37
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31535
Applikationen: X11
Update von: Ausführen beliebiger Kommandos in libx11

Originalnachricht


--===============4670926724256265745==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="45Z9DzgjV8m4Oswq"
Content-Disposition: inline


--45Z9DzgjV8m4Oswq
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4966-2
May 25, 2021

libx11 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

libx11 could allow unintended access to services.

Software Description:
- libx11: X11 client-side library

Details:

USN-4966-1 fixed a vulnerability in libx11. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

It was discovered that libx11 incorrectly validated certain parameter
lengths. A remote attacker could possibly use this issue to trick libx11
into emitting extra X protocol requests.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
libx11-6 2:1.6.3-1ubuntu2.2+esm1

Ubuntu 14.04 ESM:
libx11-6 2:1.6.2-1ubuntu2.1+esm2

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4966-2
https://ubuntu.com/security/notices/USN-4966-1
CVE-2021-31535

--45Z9DzgjV8m4Oswq
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAmCtUIUACgkQRbznW4QL
H2k6Xw/+M55A0VwoLeBHh69jwB/R2yjD00CFctyaLhQCoCdvzy3KCaczWe+Zmlke
I+nDCrMoFm1K8NFOn8U4j7Px/+acZoiXemyMUQoFEYY9vnCTYRP9FeGheCYnE1Lg
3Ks0SG/hDanXXxNKg589tyxC/cpv/mPIh9J7JhnxjSnz5OHkzxs2Gyde7yjtbX6M
BpxO3kRIzROm8gyTFuOPn8DGw2A6s8OP1YAXI0bAG6WeXIt4enqy6lT3/xtsCijw
5IEQdU24HHdpuewAG/zRX454ateMbPXsYkonur0EgaKhZ8U9Por0SBjQd2/E/nQE
9hr11CgYVHA901StQy7Ch2aFs50cDZ3AtAUFZWx4FLJlaDyxjqhCLfXbmxY1zA8i
+wfO/Ue4tgX4WtkBa8LTpIu4Xsmlnx6JuyrMf0rk88mwbR4POFp+rmjy6JzNmWG8
g4aFc0+adwuF2lgS2emdD3C1d9/jGDPYJPbcOpMo0xdx8ZLNl7Auxjf06FuF78zC
0LRT679hbDDXv3uAp5o6JRR91XtFE9XoEWBZGR+f1dxa6uagM0IxKauht09boXv1
AGDODpUOLoipJpRN4iZiN5n8LyUwT7bRugLB1RPtBLAoL2r3UY1xhzRrNn+7BAPw
DVpJaVWO0jOp7l6eZCLjSwDz8+IZaa6dN0IJr9SxCVKdzT4SOY8=
=y1P8
-----END PGP SIGNATURE-----

--45Z9DzgjV8m4Oswq--


--===============4670926724256265745==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung