Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Updated libxcursor packages fix security vulnerability _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. (CVE-2015-9262) . MGASA-2018-0364 - Updated libxcursor packages fix security vulnerability Publication date: 31 Aug 2018 URL: https://advisories.mageia.org/MGASA-2018-0364.html Type: security Affected Mageia releases: 6 CVE: CVE-2015-9262 Updated libxcursor packages fix security vulnerability _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. (CVE-2015-9262) References: - https://bugs.mageia.org/show_bug.cgi?id=23478 - https://www.openwall.com/lists/oss-security/2018/08/22/6 - https://ubuntu.com/security/notices/USN-3729-1 - https://www.cve.org/CVERecord?id=CVE-2015-9262 SRPMS: - 6/core/libxcursor-1.1.14-6.2.mga6 . MGASA-2018-0364 - Updated libxcursor packages fix security vulnerability Publication date: 31 Aug 20. updated, libxcursor, packages, security, vulnerability, _xcursorthemeinherits, library, libxcur. . LinuxSecurity.com Team
It was discovered that there was a denial of service or (potentially code execution) vulnerability in libxcursor, a library designed to help locate and load cursors for the X Window System. . Package : libxcursor Version : 1:1.1.14-1+deb8u2 CVE ID : CVE-2015-9262 Debian Bug : #906012 It was discovered that there was a denial of service or (potentially code execution) vulnerability in libxcursor, a library designed to help locate and load cursors for the X Window System. For Debian 8 "Jessie", this issue has been fixed in libxcursor version 1:1.1.14-1+deb8u2. We recommend that you upgrade your libxcursor packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
libxcursor could be made to crash or run programs if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-3729-1 August 06, 2018 libxcursor vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: libxcursor could be made to crash or run programs if it opened a specially crafted file. Software Description: - libxcursor: X11 cursor management library Details: It was discovered that libxcursor incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libxcursor1 1:1.1.14-1ubuntu0.16.04.2 Ubuntu 14.04 LTS: libxcursor1 1:1.1.14-1ubuntu0.14.04.2 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3729-1 CVE-2015-9262 Package Information: https://launchpad.net/ubuntu/+source/libxcursor/1:1.1.14-1ubuntu0.16.04.2 https://launchpad.net/ubuntu/+source/libxcursor/1:1.1.14-1ubuntu0.14.04.2 . Ubuntu Security Announcement USN-3790-1 pertains to a vulnerability in libglib that could result in application failures and service interruptions in legacy versions.. libxcursor update,ubuntu issues,security notices,crash issue. . Severity: Critical. LinuxSecurity.com Team
It was discovered that libXcursor, a X cursor management library, is prone to several heap overflows when parsing malicious files. An attacker can take advantage of these flaws for arbitrary code execution, if a user is tricked into processing a specially crafted cursor file. . Hash: SHA256 Package : libxcursor Version : 1:1.1.13-1+deb7u2 CVE ID : CVE-2017-16612 Debian Bug : 883792 It was discovered that libXcursor, a X cursor management library, is prone to several heap overflows when parsing malicious files. An attacker can take advantage of these flaws for arbitrary code execution, if a user is tricked into processing a specially crafted cursor file. For Debian 7 "Wheezy", these problems have been fixed in version 1:1.1.13-1+deb7u2. We recommend that you upgrade your libxcursor packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A recent patch for libXcursor addresses heap overflow vulnerabilities that might enable code execution through crafted cursor files.. libxcursor,heap overflow,arbitrary code execution,security update. . Severity: Important. LinuxSecurity.com Team
It was discovered that libXcursor, a X cursor management library, is prone to several heap overflows when parsing malicious files. An attacker can take advantage of these flaws for arbitrary code execution, if a user is tricked into processing a specially crafted cursor file. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4059-1
The package libxcursor before version 1.1.15-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201711-41 ========================================= Severity: High Date : 2017-11-30 CVE-ID : CVE-2017-16612 Package : libxcursor Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-531 Summary ====== The package libxcursor before version 1.1.15-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 1.1.15-1. # pacman -Syu "libxcursor> =1.1.15-1" The problem has been fixed upstream in version 1.1.15. Workaround ========= None. Description ========== It was discovered that libxcursor before 1.1.15 is vulnerable to heap overflows due to an integer overflow while parsing images and a signedness issue while parsing comments. An attacker could use local privileges or trick a user into parsing a malicious file to cause libxcursor to crash, resulting in a denial of service, or possibly execute arbitrary code. Impact ===== An attacker could use local privileges or trick a user into parsing a malicious image file to cause libxcursor to crash, resulting in a denial of service, or possibly execute arbitrary code. References ========= https://www.openwall.com/lists/oss-security/2017/11/28/6 https://marc.info/?l=freedesktop-xorg-announce&m=151188036018262&w=2 https://security.archlinux.org/CVE-2017-16612 . The Arch Linux Security Announcement ASA-202112-15 highlights a critical vulnerability allowing arbitrary code execution in libxi.. Arch Linux, LibXcursor, Code Execution, Security Advisory, Heap Overflow. . LinuxSecurity.com Team
Several security issues were fixed in libxcursor.. =========================================================================Ubuntu Security Notice USN-1856-1 June 05, 2013 libxcursor vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: Several security issues were fixed in libxcursor. Software Description: - libxcursor: X cursor management library Details: Ilja van Sprundel discovered multiple security issues in various X.org libraries and components. An attacker could use these issues to cause applications to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libxcursor1 1:1.1.13-1ubuntu0.13.04.1 Ubuntu 12.10: libxcursor1 1:1.1.13-1ubuntu0.12.10.1 Ubuntu 12.04 LTS: libxcursor1 1:1.1.12-1ubuntu0.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1856-1 CVE-2013-2003 Package Information: https://launchpad.net/ubuntu/+source/libxcursor/1:1.1.13-1ubuntu0.13.04.1 https://launchpad.net/ubuntu/+source/libxcursor/1:1.1.13-1ubuntu0.12.10.1 https://launchpad.net/ubuntu/+source/libxcursor/1:1.1.12-1ubuntu0.1 . Numerous vulnerabilities addressed in libxcursor for Ubuntu 13.04, 12.10, and 12.04. Essential instructions for updating included.. Libxcursor Security, Ubuntu Updates, Denial Of Service, Xorg Issues. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.