drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in X.Org (Aktualisierung)
Name: |
Mehrere Probleme in X.Org (Aktualisierung) |
|
ID: |
USN-6587-5 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 14.04 LTS (Available with Ubuntu Pro) |
|
Datum: |
Mi, 13. März 2024, 23:21 |
|
Referenzen: |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6478
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6816
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21886
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0409
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21885
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0229
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0408 |
|
Applikationen: |
X11 |
|
Update von: |
Mehrere Probleme in X.Org |
|
Originalnachricht |
--===============6449848113721651793== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="qDbXVdCdHGoSgWSk" Content-Disposition: inline
--qDbXVdCdHGoSgWSk Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-6587-5 March 13, 2024
xorg-server vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS (Available with Ubuntu Pro)
Summary:
Several security issues were fixed in X.Org X Server.
Software Description: - xorg-server: X.Org X11 server
Details:
USN-6587-1 fixed several vulnerabilities in X.Org. This update provides the corresponding update for Ubuntu 14.04 LTS.
Original advisory details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled memory when processing the RRChangeOutputProperty and RRChangeProviderProperty APIs. An attacker could possibly use this issue to cause the X Server to crash, or obtain sensitive information. (CVE-2023-6478)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled memory when processing the DeviceFocusEvent and ProcXIQueryPointer APIs. An attacker could possibly use this issue to cause the X Server to crash, obtain sensitive information, or execute arbitrary code. (CVE-2023-6816)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled reattaching to a different master device. An attacker could use this issue to cause the X Server to crash, leading to a denial of service, or possibly execute arbitrary code. (CVE-2024-0229)
Olivier Fourdan and Donn Seeley discovered that the X.Org X Server incorrectly labeled GLX PBuffers when used with SELinux. An attacker could use this issue to cause the X Server to crash, leading to a denial of service. (CVE-2024-0408)
Olivier Fourdan discovered that the X.Org X Server incorrectly handled the curser code when used with SELinux. An attacker could use this issue to cause the X Server to crash, leading to a denial of service. (CVE-2024-0409)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled memory when processing the XISendDeviceHierarchyEvent API. An attacker could possibly use this issue to cause the X Server to crash, or execute arbitrary code. (CVE-2024-21885)
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled devices being disabled. An attacker could possibly use this issue to cause the X Server to crash, or execute arbitrary code. (CVE-2024-21886)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.04 LTS (Available with Ubuntu Pro): xserver-xorg-core 2:1.15.1-0ubuntu2.11+esm9
After a standard system update you need to reboot your computer to make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-6587-5 https://ubuntu.com/security/notices/USN-6587-1 CVE-2023-6478, CVE-2023-6816, CVE-2024-0229, CVE-2024-0408, CVE-2024-21885, CVE-2024-21886
--qDbXVdCdHGoSgWSk Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAmXyGIcACgkQRbznW4QL H2k6mhAAgNftz8rP6ytQBKC3BCtuh4hKXRFJPDitu4cd0PBcaDmjqsqWFYR1t0aS V7lp1E0opbQntzQeKEWkRS4IkgRQv3QUXDEa9rH/F+Wz2JKIlfEIauhPyKu0dsPY yU1XxWGaNly44Il0u/Gb7RdfGM1BzxMOvPXl/IYlUL8GYZCgjEP4fVn06nM2kXr9 n7j5x3HDbNLnPCkapsO5proDuilax8+j1cLA48oCQJufOMtqLwOz1AoktqirjuWa X1CNVHUR3OPt2oWYbzx4o6cjiqkbR1SS2ddanoTaDNQeDJApQvWrtXtR4U6NmFDM wQdGxJlNcofYFEnxZZWLib3qqAhuXjXqAq8kt703YUWUR7k6vuMIjm+oakr1NHVL V9uSzx11p8BkSOQgzvTSjI8e58gA4SpPVeVYpSoiayTB+ybXXNK1v64VMPQ6R7+h Mtj3J91yfRqTsG0uFzSKOGqJ85QAUAjQXsqE2+P3pCCUvNbgxlnwDgutLRt1svXD FnoDcc2Tz8FZUNG4d6ssMgRylNO4IW/8Tv64BX+q7Vjo6KZLg8mY4X8UG01oy9Kd DHPOPsnzm2nSHtV4JeuxUbDgxZdgaieBOnDKjAhb/W3rUtdVvGwgwfvZaXiYeVoH 1Agf1xamgIF6BmLNvMqEGzprcOsFcJzXHsxD9Gj4M0oz6DgMvKw= =Aliy -----END PGP SIGNATURE-----
--qDbXVdCdHGoSgWSk--
--===============6449848113721651793== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
--===============6449848113721651793==--
|
|
|
|