=========================================================================Ubuntu Security Notice USN-5744-1
November 28, 2022

libice vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM

Summary:

Weak session cookies generated using libICE could allow sensitive
information to be exposed.

Software Description:
- libice: X11 Inter-Client Exchange library (development headers)

Details:

It was discovered that libICE was using a weak mechanism to generate the
session cookies. A local attacker could possibly use this issue to perform
a privilege escalation attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  libice-dev                      2:1.0.9-2ubuntu0.18.04.1
  libice6                         2:1.0.9-2ubuntu0.18.04.1

Ubuntu 16.04 ESM:
  libice-dev                      2:1.0.9-1ubuntu0.16.04.1+esm1
  libice6                         2:1.0.9-1ubuntu0.16.04.1+esm1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5744-1
  CVE-2017-2626

Package Information:
  https://launchpad.net/ubuntu/+source/libice/2:1.0.9-2ubuntu0.18.04.1

Ubuntu 5744-1: libICE vulnerability

November 28, 2022
Weak session cookies generated using libICE could allow sensitive information to be exposed.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libice-dev 2:1.0.9-2ubuntu0.18.04.1 libice6 2:1.0.9-2ubuntu0.18.04.1 Ubuntu 16.04 ESM: libice-dev 2:1.0.9-1ubuntu0.16.04.1+esm1 libice6 2:1.0.9-1ubuntu0.16.04.1+esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5744-1

CVE-2017-2626

Severity
November 28, 2022

Package Information

https://launchpad.net/ubuntu/+source/libice/2:1.0.9-2ubuntu0.18.04.1

Related News