Security fix for CVE-2016-7951, CVE-2016-7952. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-e6ba110670 2016-10-10 17:40:40.897988 -------------------------------------------------------------------------------- Name : libXtst Product : Fedora 25 Version : 1.2.3 Release : 1.fc25 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXtst runtime library Description : X.Org X11 libXtst runtime library -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-7951, CVE-2016-7952 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381919 - CVE-2016-7951 libXtst: Insufficient validation of server responses result in Integer overflows https://bugzilla.redhat.com/show_bug.cgi?id=1381919 [ 2 ] Bug #1381922 - CVE-2016-7952 libXtst: Insufficient validation of server responses result in various data mishandlings https://bugzilla.redhat.com/show_bug.cgi?id=1381922 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libXtst' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several security issues were fixed in libxtst.. =========================================================================Ubuntu Security Notice USN-1866-1 June 05, 2013 libxtst vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: Several security issues were fixed in libxtst. Software Description: - libxtst: X11 Record extension library Details: Ilja van Sprundel discovered multiple security issues in various X.org libraries and components. An attacker could use these issues to cause applications to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libxtst6 2:1.2.1-1ubuntu0.13.04.1 Ubuntu 12.10: libxtst6 2:1.2.1-1ubuntu0.12.10.1 Ubuntu 12.04 LTS: libxtst6 2:1.2.0-4ubuntu0.1 Ubuntu 10.04 LTS: libxtst6 2:1.1.0-2ubuntu0.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1866-1 CVE-2013-2063 Package Information: https://launchpad.net/ubuntu/+source/libxtst/2:1.2.1-1ubuntu0.13.04.1 https://launchpad.net/ubuntu/+source/libxtst/2:1.2.1-1ubuntu0.12.10.1 https://launchpad.net/ubuntu/+source/libxtst/2:1.2.0-4ubuntu0.1 https://launchpad.net/ubuntu/+source/libxtst/2:1.1.0-2ubuntu0.1 . Tackling weaknesses in libxtst across various Ubuntu editions to strengthen security measures and mitigate exploitation risks.. Ubuntu Security, libxtst Update, Denial of Service Fix. . Severity: Critical. LinuxSecurity.com Team
Ilja van Sprundel of IOActive discovered several security issues in multiple components of the X.org graphics stack and the related libraries: Various integer overflows, sign handling errors in integer conversions, buffer overflows, memory corruption and missing input . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2689-1
Get the latest Linux and open source security news straight to your inbox.