Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Xcftools could be made to crash or run programs as an administrator
if it opened a specially crafted file.
Software Description:
- xcftools: command-line tools for extracting data for XCF files
Details:
It was discovered that integer overflows vulnerabilities existed in Xcftools.
An attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2019-5086, CVE-2019-5087)
The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: xcftools 1.0.7-6ubuntu0.20.04.1 Ubuntu 18.04 LTS: xcftools 1.0.7-6ubuntu0.1 Ubuntu 16.04 ESM: xcftools 1.0.7-5ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-5988-1
CVE-2019-5086, CVE-2019-5087
Get the latest Linux and open source security news straight to your inbox.