Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Ubuntu 10.04 LTS, 10.10 USN-1232-3 Critical X.Org X Server DoS

ubuntu
Calendar Grey October 20, 2011
Scroller Ubuntu
The Ubuntu Security Notice USN-4567-8 highlights vulnerabilities in the xorg-server that impact several Ubuntu editions.
The X server could be made to crash or run programs as an administrator.

Summary

The X server could be made to crash or run programs as an administrator.

Software Description:

- xorg-server: X.Org X server

Details:

USN-1232-1 fixed vulnerabilities in the X.Org X server. A regression was

found on Ubuntu 10.04 LTS that affected GLX support, and USN-1232-2 was

released to temporarily disable the problematic security fix. This update

includes a revised fix for CVE-2010-4818.

We apologize for the inconvenience.

Original advisory details:

It was discovered that the X server incorrectly handled certain malformed

input. An authorized attacker could exploit this to cause the X server to

crash, leading to a denial or service, or possibly execute arbitrary code

with root privileges. This issue only affected Ubuntu 10.04 LTS and 10.10.

(CVE-2010-4818)

It was discovered that the X server incorrectly handled certain malformed

input. An authorized attacker could exploit this to cause the X server to

crash, leading to a denial or servic...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.10:
  xserver-xorg-core               2:1.9.0-0ubuntu7.6

Ubuntu 10.04 LTS:
  xserver-xorg-core               2:1.7.6-2ubuntu7.10

After a standard system update you need to restart your session to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1232-3

https://ubuntu.com/security/notices/USN-1232-1

CVE-2010-4818

Severity
critical
Lowest
Low
Medium
High
Critical

October 20, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.