Explore top 10 tips to secure your open-source projects now. Read More
×Several security issues were fixed in libx11.. ========================================================================== Ubuntu Security Notice USN-6407-2 October 10, 2023 libx11 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in libx11. Software Description: - libx11: X11 client-side library Details: USN-6407-1 fixed several vulnerabilities in libx11. This update provides the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: Gregory James Duck discovered that libx11 incorrectly handled certain keyboard symbols. If a user were tricked into connecting to a malicious X server, a remote attacker could use this issue to cause libx11 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-43785) Yair Mizrahi discovered that libx11 incorrectly handled certain malformed XPM image files. If a user were tricked into opening a specially crafted XPM image file, a remote attacker could possibly use this issue to consume memory, leading to a denial of service. (CVE-2023-43786) Yair Mizrahi discovered that libx11 incorrectly handled certain malformed XPM image files. If a user were tricked into opening a specially crafted XPM image file, a remote attacker could use this issue to cause libx11 to crash, leading to a denial of service, or possibly execute arbitrary code. (CVE-2023-43787) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS (Available with Ubuntu Pro): libx11-6 2:1.6.4-3ubuntu0.4+esm2 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libx11-6 2:1.6.3-1ubuntu2.2+esm4 Ubuntu 14.04LTS (Available with Ubuntu Pro): libx11-6 2:1.6.2-1ubuntu2.1+esm5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6407-2 https://ubuntu.com/security/notices/USN-6407-1 CVE-2023-43785, CVE-2023-43786, CVE-2023-43787 . Explore the latest Ubuntu Security Notice USN-6407-3, which tackles vulnerabilities in libx11 impacting various versions.. libx11 Issues, Remote Code Execution, Denial Of Service, Ubuntu Advisory. . LinuxSecurity.com Team
Multiple security vulnerabilities were discovered in libx11, the X11 client-side library, which may result in denial of service or the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5517-1
Several vulnerabilities were found in libx11, the X11 client-side library. CVE-2023-43785 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3602-1
Several security issues were fixed in libx11.. ========================================================================== Ubuntu Security Notice USN-6407-1 October 03, 2023 libx11 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in libx11. Software Description: - libx11: X11 client-side library Details: Gregory James Duck discovered that libx11 incorrectly handled certain keyboard symbols. If a user were tricked into connecting to a malicious X server, a remote attacker could use this issue to cause libx11 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-43785) Yair Mizrahi discovered that libx11 incorrectly handled certain malformed XPM image files. If a user were tricked into opening a specially crafted XPM image file, a remote attacker could possibly use this issue to consume memory, leading to a denial of service. (CVE-2023-43786) Yair Mizrahi discovered that libx11 incorrectly handled certain malformed XPM image files. If a user were tricked into opening a specially crafted XPM image file, a remote attacker could use this issue to cause libx11 to crash, leading to a denial of service, or possibly execute arbitrary code. (CVE-2023-43787) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: libx11-6 2:1.8.4-2ubuntu0.3 Ubuntu 22.04 LTS: libx11-6 2:1.7.5-1ubuntu0.3 Ubuntu 20.04 LTS: libx11-6 2:1.6.9-2ubuntu1.6 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6407-1 CVE-2023-43785, CVE-2023-43786, CVE-2023-43787 Package Information: https://launchpad.net/ubuntu/+source/libx11/2:1.8.4-2ubuntu0.3 https://launchpad.net/ubuntu/+source/libx11/2:1.7.5-1ubuntu0.3 https://launchpad.net/ubuntu/+source/libx11/2:1.6.9-2ubuntu1.6 . Multiple libx11 vulnerabilities addressed for Ubuntu versions 20.04, 22.04, and 23.04 LTS. Update promptly to prevent service disruptions.. libx11 Security, Ubuntu Denial Of Service, Ubuntu Patch, Security Update, Software Fix. . LinuxSecurity.com Team
Missing input validation in various functions may have resulted in denial of service in various functions provided by libx11, the X11 client-side library. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3472-1
Gregory James Duck reported that missing input validation in various functions provided by libx11, the X11 client-side library, may result in denial of service. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5433-1
libx11 could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-6168-2 June 20, 2023 libx11 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: libx11 could be made to crash if it received specially crafted network traffic. Software Description: - libx11: X11 client-side library Details: USN-6168-1 fixed a vulnerability in libx11. This update provides the corresponding update for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 ESM. Original advisory details: Gregory James Duck discovered that libx11 incorrectly handled certain Request, Event, or Error IDs. If a user were tricked into connecting to a malicious X Server, a remote attacker could possibly use this issue to cause libx11 to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS (Available with Ubuntu Pro): libx11-6 2:1.6.4-3ubuntu0.4+esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libx11-6 2:1.6.3-1ubuntu2.2+esm2 Ubuntu 14.04 LTS (Available with Ubuntu Pro): libx11-6 2:1.6.2-1ubuntu2.1+esm3 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6168-2 https://ubuntu.com/security/notices/USN-6168-1 CVE-2023-3138 . Explore the USN-6168-2 notification regarding security flaws in libx11 that impact Ubuntu systems. Find out about the specifics of the update and its level of risk.. libx11, Denial Of Service, Ubuntu Advisory, Security Issues. . Severity: Critical.LinuxSecurity.com Team
libX11 1.8.6 (CVE-2023-3138). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-7503ce855c 2023-06-18 01:29:01.914214 --------------------------------------------------------------------------------Name : libX11 Product : Fedora 38 Version : 1.8.6 Release : 1.fc38 URL : https://www.x.org/wiki/ Summary : Core X11 protocol client library Description : Core X11 protocol client library. --------------------------------------------------------------------------------Update Information: libX11 1.8.6 (CVE-2023-3138) --------------------------------------------------------------------------------ChangeLog: * Fri Jun 16 2023 Peter Hutterer - 1.8.6-1 - libX11 1.8.6 (CVE-2023-3138) * Mon Jun 5 2023 Peter Hutterer 1.8.5-1 - libX11 1.8.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #2213748 - CVE-2023-3138 libX11: InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=2213748 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7503ce855c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.