Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in libXrender
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in libXrender
ID: USN-5436-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 ESM
Datum: Mo, 23. Mai 2022, 22:29
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7950
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7949
Applikationen: X11

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8393068927358235370==
Content-Language: en-US
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="------------N3LubTz2cIfEX0XgtOqDzp4I"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------------N3LubTz2cIfEX0XgtOqDzp4I
Content-Type: multipart/mixed;
boundary="------------U89KdRs4qfHiDDdPq56Q4o0Q";
protected-headers="v1"
From: Rodrigo Figueiredo Zaiden <rodrigo.zaiden@canonical.com>
Reply-To: security@ubuntu.com
To: ubuntu-security-announce@lists.ubuntu.com
Message-ID: <87b88563-c29b-3011-2998-e54176db1afe@canonical.com>
Subject: [USN-5436-1] libXrender vulnerabilities

--------------U89KdRs4qfHiDDdPq56Q4o0Q
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: base64

==========================================================================
Ubuntu Security Notice USN-5436-1
May 23, 2022

libxrender vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM

Summary:

Several security issues were fixed in libXrender.

Software Description:
- libxrender: X11 Rendering Extension client library

Details:

Tobias Stoeckmann discovered that libXrender incorrectly handled certain
responses. An attacker could possibly use this issue to cause a denial
of service, or possibly execute arbitrary code.
(CVE-2016-7949, CVE-2016-7950)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
libxrender1 1:0.9.9-0ubuntu1+esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5436-1
CVE-2016-7949, CVE-2016-7950
--------------U89KdRs4qfHiDDdPq56Q4o0Q--

--------------N3LubTz2cIfEX0XgtOqDzp4I
Content-Type: application/pgp-signature; name="OpenPGP_signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="OpenPGP_signature"

-----BEGIN PGP SIGNATURE-----

wsB5BAABCAAjFiEEYrygdx1GDec9TV8EZ0GeRcM5nt0FAmKL078FAwAAAAAACgkQZ0GeRcM5nt2E
Fwf8Cfm3oPPGThkNo03OyG9rgdCY8QwiHYILxZxuJXoiXh3iNE99I8L2lenrttGQsg2imP8AQuCF
bXkeFUfcG/8E2HPHI1fXkwDBN+dq7sGwhemCTcOGbbck7IhbPZPFQm0j3y2R0BbdoXBuI/3sEzZb
ZdDVyT6D8CZOXkJF0ypf7VrfSiHvnVhrQCm69TmSl3TSjwD2SlZGQXbpBjVfjpoUUpPm80uWu8Cp
fESsGqnbcYnWRjSvGsBM/9jZFdbtA7ZgsWG9zTV62q10wtLaHwf0VL2BeNlgM2tSHBkdDwBVCNkc
kXRRDiavpA7C1pfKEdjY7STZb8YCAbdxkDy6nhCEhQ==
=YgAq
-----END PGP SIGNATURE-----

--------------N3LubTz2cIfEX0XgtOqDzp4I--


--===============8393068927358235370==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============8393068927358235370==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung