|
|
Log in / Subscribe / Register

Ubuntu alert USN-3453-1 (xorg-server, xorg-server-hwe-16.04, xorg-server-lts-xenial)

From:  Marc Deslauriers <marc.deslauriers@canonical.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-3453-1] X.Org X server vulnerabilities
Date:  Thu, 12 Oct 2017 11:13:34 -0400
Message-ID:  <d89cb853-4003-bc73-cbc9-6f5c74df8d7d@canonical.com>

========================================================================== Ubuntu Security Notice USN-3453-1 October 12, 2017 xorg-server, xorg-server-hwe-16.04, xorg-server-lts-xenial vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in the X.Org X server. Software Description: - xorg-server: X.Org X11 server - xorg-server-hwe-16.04: X.Org X11 server - xorg-server-lts-xenial: X.Org X11 server Details: Michal Srb discovered that the X.Org X server incorrectly handled shared memory segments. An attacker able to connect to an X server, either locally or remotely, could use this issue to crash the server, or possibly replace shared memory segments of other X clients in the same session. (CVE-2017-13721) Michal Srb discovered that the X.Org X server incorrectly handled XKB buffers. An attacker able to connect to an X server, either locally or remotely, could use this issue to crash the server, or possibly execute arbitrary code. (CVE-2017-13723) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: xserver-xorg-core 2:1.19.3-1ubuntu1.2 Ubuntu 16.04 LTS: xserver-xorg-core 2:1.18.4-0ubuntu0.6 xserver-xorg-core-hwe-16.04 2:1.19.3-1ubuntu1~16.04.3 Ubuntu 14.04 LTS: xserver-xorg-core 2:1.15.1-0ubuntu2.10 xserver-xorg-core-lts-xenial 2:1.18.3-1ubuntu2.3~trusty3 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://www.ubuntu.com/usn/usn-3453-1 CVE-2017-13721, CVE-2017-13723 Package Information: https://launchpad.net/ubuntu/+source/xorg-server/2:1.19.3... https://launchpad.net/ubuntu/+source/xorg-server/2:1.18.4... https://launchpad.net/ubuntu/+source/xorg-server-hwe-16.0... https://launchpad.net/ubuntu/+source/xorg-server/2:1.15.1... https://launchpad.net/ubuntu/+source/xorg-server-lts-xeni... -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security...


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds