Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 12.04 USN-1502-1 Critical: X.Org X Server DoS Risk

ubuntu
Calendar Grey July 11, 2012
Scroller Ubuntu
A flaw in the X.Org server affects Ubuntu 12.04 LTS, allowing a possible system crash triggered by specially formed input device data.
The X.Org X server could be made to crash if a specially crafted inputdevice was added.

Summary

The X.Org X server could be made to crash if a specially crafted input

device was added.

Software Description:

- xorg-server: X.Org X server

Details:

Ken Mixter discovered a format string vulnerability in the

LogVHdrMessageVerb function when handling input device names. This

could allow a local attacker to cause a denial of service or possibly

execute arbitrary code.

The default compiler options for the affected release should reduce

the vulnerability to a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  xserver-xorg-core               2:1.11.4-0ubuntu10.5

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1502-1

CVE-2012-2118

Severity
critical
Lowest
Low
Medium
High
Critical

July 11, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.