Security fix for CVE-2016-7944. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-72d7f05b90 2016-10-10 17:40:40.899222 -------------------------------------------------------------------------------- Name : libXfixes Product : Fedora 25 Version : 5.0.3 Release : 1.fc25 URL : https://www.x.org/wiki/ Summary : X Fixes library Description : X Fixes library. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-7944 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381865 - CVE-2016-7944 libXfixes: Insufficient validation of server responses results in Integer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1381865 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libXfixes' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several security issues were fixed in libxfixes.. =========================================================================Ubuntu Security Notice USN-1858-1 June 05, 2013 libxfixes vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: Several security issues were fixed in libxfixes. Software Description: - libxfixes: X11 miscellaneous fixes extension library Details: Ilja van Sprundel discovered multiple security issues in various X.org libraries and components. An attacker could use these issues to cause applications to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libxfixes3 1:5.0-4ubuntu5.13.04.1 Ubuntu 12.10: libxfixes3 1:5.0-4ubuntu5.12.10.1 Ubuntu 12.04 LTS: libxfixes3 1:5.0-4ubuntu4.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1858-1 CVE-2013-1983 Package Information: https://launchpad.net/ubuntu/+source/libxfixes/1:5.0-4ubuntu5.13.04.1 https://launchpad.net/ubuntu/+source/libxfixes/1:5.0-4ubuntu5.12.10.1 https://launchpad.net/ubuntu/+source/libxfixes/1:5.0-4ubuntu4.1 . Numerous vulnerabilities addressed in libxfixes for Ubuntu, impacting releases 14.04, 13.10, and 12.04 LTS.. libxfixes Update, Ubuntu 13.04 Advisory, Security Issues. . Severity: Critical. LinuxSecurity.com Team
Ilja van Sprundel of IOActive discovered several security issues in multiple components of the X.org graphics stack and the related libraries: Various integer overflows, sign handling errors in integer conversions, buffer overflows, memory corruption and missing input . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2676-1
Get the latest Linux and open source security news straight to your inbox.