Security fix for CVE-2016-7953. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-37b9932690 2016-10-10 17:40:40.895426 -------------------------------------------------------------------------------- Name : libXvMC Product : Fedora 25 Version : 1.0.10 Release : 1.fc25 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXvMC runtime library Description : X.Org X11 libXvMC runtime library -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-7953 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381933 - CVE-2016-7953 libXvMC: Insufficient validation of server responses results in buffer underflow https://bugzilla.redhat.com/show_bug.cgi?id=1381933 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libXvMC' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several security issues were fixed in libxvmc.. =========================================================================Ubuntu Security Notice USN-1868-1 June 05, 2013 libxvmc vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: Several security issues were fixed in libxvmc. Software Description: - libxvmc: X11 Video extension library Details: Ilja van Sprundel discovered multiple security issues in various X.org libraries and components. An attacker could use these issues to cause applications to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libxvmc1 2:1.0.7-1ubuntu1.13.04.1 Ubuntu 12.10: libxvmc1 2:1.0.7-1ubuntu1.12.10.1 Ubuntu 12.04 LTS: libxvmc1 2:1.0.6-1ubuntu2.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1868-1 CVE-2013-1990, CVE-2013-1999 Package Information: https://launchpad.net/ubuntu/+source/libxvmc/2:1.0.7-1ubuntu1.13.04.1 https://launchpad.net/ubuntu/+source/libxvmc/2:1.0.7-1ubuntu1.12.10.1 https://launchpad.net/ubuntu/+source/libxvmc/2:1.0.6-1ubuntu2.1 . Various vulnerabilities identified in libxvmc pose serious crash and code execution threats, especially important for Ubuntu systems.. libxvmc Security Update, Ubuntu 12.04 LTS Patch, Libxvmc Critical Advisory. . Severity: Critical. LinuxSecurity.com Team
A regression was discovered in the security update for libxvmc, causing segfaults with some applications. Updated packages are available to address this problem. For reference, the original advisory text follows. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2675-2
Ilja van Sprundel of IOActive discovered several security issues in multiple components of the X.org graphics stack and the related libraries: Various integer overflows, sign handling errors in integer conversions, buffer overflows, memory corruption and missing input . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2675-1
Get the latest Linux and open source security news straight to your inbox.