libXv could be made to crash or run programs if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5449-1 May 26, 2022 libxv vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: libXv could be made to crash or run programs if it received specially crafted input. Software Description: - libxv: X11 Video extension library Details: It was discovered that libXv incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libxv1 2:1.0.10-1ubuntu0.16.04.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5449-1 CVE-2016-5407 . Ubuntu 16.04 ESM encounters a severe libXv vulnerability leading to system instability or application exploitation via harmful inputs.. Ubuntu Security, libXv Issue, Denial Of Service, Code Execution. . Severity: Critical. LinuxSecurity.com Team
Security fix for CVE-2016-5407. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-5aa206bd16 2016-10-09 02:26:44.529418 -------------------------------------------------------------------------------- Name : libXv Product : Fedora 24 Version : 1.0.11 Release : 1.fc24 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXv runtime library Description : X.Org X11 libXv runtime library -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-5407 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381931 - CVE-2016-5407 libXv: Insufficient validation of server responses results in out-of bounds accesses https://bugzilla.redhat.com/show_bug.cgi?id=1381931 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libXv' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several security issues were fixed in libxv.. =========================================================================Ubuntu Security Notice USN-1867-1 June 05, 2013 libxv vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: Several security issues were fixed in libxv. Software Description: - libxv: X11 Video extension library Details: Ilja van Sprundel discovered multiple security issues in various X.org libraries and components. An attacker could use these issues to cause applications to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libxv1 2:1.0.7-1ubuntu0.13.04.1 Ubuntu 12.10: libxv1 2:1.0.7-1ubuntu0.12.10.1 Ubuntu 12.04 LTS: libxv1 2:1.0.6-2ubuntu0.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1867-1 CVE-2013-1989, CVE-2013-2066 Package Information: https://launchpad.net/ubuntu/+source/libxv/2:1.0.7-1ubuntu0.13.04.1 https://launchpad.net/ubuntu/+source/libxv/2:1.0.7-1ubuntu0.12.10.1 https://launchpad.net/ubuntu/+source/libxv/2:1.0.6-2ubuntu0.1 . Ubuntu Security Alert USN-1867-1 has been issued to resolve several vulnerabilities in libxv that impact different versions of the Ubuntu operating system.. Ubuntu Security Notice, libxv, Denial of Service, Code Execution. . Severity: Critical. LinuxSecurity.com Team
Ilja van Sprundel of IOActive discovered several security issues in multiple components of the X.org graphics stack and the related libraries: Various integer overflows, sign handling errors in integer conversions, buffer overflows, memory corruption and missing input . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2674-1
Get the latest Linux and open source security news straight to your inbox.