drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in X.Org
Name: |
Ausführen beliebiger Kommandos in X.Org |
|
ID: |
USN-4490-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS |
|
Datum: |
Di, 8. September 2020, 22:26 |
|
Referenzen: |
https://launchpad.net/ubuntu/+source/xorg-server-hwe-18.04/2:1.20.8-2ubuntu2.2~18.04.3
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14345
https://launchpad.net/ubuntu/+source/xorg-server-hwe-16.04/2:1.19.6-1ubuntu4.1~16.04.4 |
|
Applikationen: |
X11 |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============3004965179233016966== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="CnI6Goz0rLukBi1X7ktocaNrw0FDio8VQ"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --CnI6Goz0rLukBi1X7ktocaNrw0FDio8VQ Content-Type: multipart/mixed; boundary="RRQZWz1eic5MNv9cl3FwWZWAvB5aXgjSf"
--RRQZWz1eic5MNv9cl3FwWZWAvB5aXgjSf Content-Type: text/plain; charset=utf-8 Content-Language: en-C Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-4490-1 September 08, 2020
xorg-server, xorg-server-hwe-16.04, xorg-server-hwe-18.04 vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS
Summary:
X.Org X Server could be made to crash or run programs if it received specially crafted input.
Software Description: - xorg-server: X.Org X11 server - xorg-server-hwe-18.04: X.Org X11 server - xorg-server-hwe-16.04: X.Org X11 server
Details:
Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled the XkbSetNames function. A local attacker could possibly use this issue to escalate privileges.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04 LTS: xserver-xorg-core 2:1.20.8-2ubuntu2.4
Ubuntu 18.04 LTS: xserver-xorg-core 2:1.19.6-1ubuntu4.6 xserver-xorg-core-hwe-18.04 2:1.20.8-2ubuntu2.2~18.04.3
Ubuntu 16.04 LTS: xserver-xorg-core 2:1.18.4-0ubuntu0.10 xserver-xorg-core-hwe-16.04 2:1.19.6-1ubuntu4.1~16.04.4
After a standard system update you need to reboot your computer to make all the necessary changes.
References: https://usn.ubuntu.com/4490-1 CVE-2020-14345
Package Information: https://launchpad.net/ubuntu/+source/xorg-server/2:1.20.8-2ubuntu2.4 https://launchpad.net/ubuntu/+source/xorg-server/2:1.19.6-1ubuntu4.6
https://launchpad.net/ubuntu/+source/xorg-server-hwe-18.04/2:1.20.8-2ubuntu2.2~18.04.3 https://launchpad.net/ubuntu/+source/xorg-server/2:1.18.4-0ubuntu0.10
https://launchpad.net/ubuntu/+source/xorg-server-hwe-16.04/2:1.19.6-1ubuntu4.1~16.04.4
--RRQZWz1eic5MNv9cl3FwWZWAvB5aXgjSf--
--CnI6Goz0rLukBi1X7ktocaNrw0FDio8VQ Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl9XgW8ACgkQZWnYVadE vpOjMRAAoFYH+xTGQyrtCronIjOkILhub/s+PK4r3ZKiPfnmFhVhDJYBDOcUkxQL yJZHhGz0mqHgIC56WoLopuWIeLSx8BI2k5AXDN2Et3KbZY/1OpsQ042arrQh9f0i DH2XjZK6s3D9yM9yNB2i8FefJjNOQRJKdhnVarw30ElHAA15zz05mI0yxnIBYJnC Ysz9IFsbmeefKggRsToGnd9j0UUymji6BFnNQHH0fCch8QszuRJJgf0sd2fIpTU4 l8yongRKTtIEeJBX5mFDUODLKaDPC0g7bYJ8GYbe80R4EUxaswbPGhlswDvhwK1w h5lnwRYD7J5HuHNFdDUCQfxr6jWZaEeDUYh2yENKVjJcMRcpZ6erykKTYxtoOS/m d9uzFBuOwRzygsqTegaoCQbyvx/MHS1OoNLvvLf+C1OeSBwbnuzqULSkeopcuOIp mTSdOSHyIaF46L+yhL53PsSqccwcdXs1xmuEz7SPhGLNU0S8txHlbhF9MVtlgUgn be7AeCWilZq7tsDwHJJhfIdkfkXrlhHwwFbrNmXLGQ3E/NGgZS0h2+YgClXF21M4 KomdCgUs0ezT+cIVL42AMLciRx/kYWviZZDvBm0SGs9mE+y3Ob1XpRAJQ79Ekqis fvnbJhWA8lqP229nYJC72dcGKMa1xApKs7b56zLf2xbl6BTsBC8= =Y1N3 -----END PGP SIGNATURE-----
--CnI6Goz0rLukBi1X7ktocaNrw0FDio8VQ--
--===============3004965179233016966== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK
--===============3004965179233016966==--
|
|
|
|