=========================================================================Ubuntu Security Notice USN-5718-2
November 30, 2022

pixman vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

pixman could be made to crash or run programs if it processed specially
crafted input.

Software Description:
- pixman: pixel-manipulation library for X and cairo

Details:

USN-5718-1 fixed a vulnerability in pixman. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

  Maddie Stone discovered that pixman incorrectly handled certain memory
  operations. A remote attacker could use this issue to cause pixman to
  crash, resulting in a denial of service, or possibly execute arbitrary
  code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
   libpixman-1-0                   0.33.6-1ubuntu0.1~esm1
   libpixman-1-dev                 0.33.6-1ubuntu0.1~esm1

Ubuntu 14.04 ESM:
   libpixman-1-0                   0.30.2-2ubuntu1.2+esm1
   libpixman-1-dev                 0.30.2-2ubuntu1.2+esm1

After a standard system update you need to restart your session to make
all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-5718-2
   https://ubuntu.com/security/notices/USN-5718-1
   CVE-2022-44638

Ubuntu 5718-2: pixman vulnerability

November 30, 2022
pixman could be made to crash or run programs if it processed specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM:   libpixman-1-0                   0.33.6-1ubuntu0.1~esm1   libpixman-1-dev                 0.33.6-1ubuntu0.1~esm1 Ubuntu 14.04 ESM:   libpixman-1-0                   0.30.2-2ubuntu1.2+esm1   libpixman-1-dev                 0.30.2-2ubuntu1.2+esm1 After a standard system update you need to restart your session to make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-5718-2

  https://ubuntu.com/security/notices/USN-5718-1

  CVE-2022-44638

Severity
November 30, 2022

Package Information

Related News