|
|
Log in / Subscribe / Register

Ubuntu alert USN-7965-1 (simgear)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7965-1] SimGear vulnerability
Date:  Thu, 15 Jan 2026 18:17:45 +0000
Message-ID:  <E1vgRuj-0004AK-9S@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7965-1 January 15, 2026 simgear vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: SimGear could be made to run programs as an administrator if it opened a specially crafted file. Software Description: - simgear: set of open-source libraries for assembling 3d simulations, games, and visualizations Details: It was discovered that SimGear could be made to bypass the sandboxing of Nasal scripts. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libsimgear-dev 1:2020.3.18+dfsg-2.1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libsimgear-dev 1:2020.3.6+dfsg-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS libsimgear-dev 1:2019.1.1+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libsimgear-dev 1:2018.1.1+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libsimgear-dev 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro libsimgearcore3.4.0v5 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro libsimgearscene3.4.0v5 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7965-1 CVE-2025-0781


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmlpLpIACgkQcpJm3tlz hgElBA/+McP1iButWsC2dyVvWk1k/aa98LIWFN+YgfxM6b3rJq230EZcTHf+MHYu sV901aDkEswsbLCGLffLLvykIN9Foz5Bg0flekbMmQmRG2zfxeR+cKupzAwW5ZVC znv4706U7yN2f+KU+DutAgMsUl7hD+Ifg5gCma+5w3mHM8gvlFfJ5t8Z6XMcRHXp ZRm94kinj/W8+ykIBcq7wHg9VEZeD63NeCNMcdmfwZghyeGOw+hgzmGMPDuvM++s BIeWRcyEEXH2aGpGqNB4J8+mSH/glCd25cG3yRT84o1IXZlD85t8tMFA8egrzZap GJ7DAK5SHCwsfKiAWfnH46ndj/4IbRNiBawdWQD4Q9za0OqVfKl7gOcir3sRtkag t9ZOpH2d6EEbzRaGvLeyckVucwtZEwDbdufXBAVa/s1Hlg9Be4e57h5eJVXlpNP9 lzsDSO0DbuaawycaW4DtzSdzEwNuk9XtRlnUo6smgX+tDh2mEDbsh1ZD0U3Lh4zc KUpiqrUdnn3TEYUYhzlbyNcCUxqWzQ8LgZ8I7zk3cyDaUp5VJCf2I3iF09Pnb8lo z+3jzMdGidtCTWYra49QYTOnvSnfN4NCGETOtiBnipJwcV5ng2JZE43ow2X+OFkW xS7t0fk+ZFaK6wRp9Rd3n1fFQk4kwgpXVCLctTBZR7hrPO5sgd4= =PabV -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds