Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201801-04 ] LibXcursor: User-assisted execution of arbitrary code
Date: Sun, 07 Jan 2018 23:31:58
Message-Id: 2718578.oKxB3fxIjP@localhost.localdomain
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201801-04
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: LibXcursor: User-assisted execution of arbitrary code
9 Date: January 07, 2018
10 Bugs: #639062
11 ID: 201801-04
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability in LibXcursor might allow remote attackers to execute
19 arbitrary code.
20
21 Background
22 ==========
23
24 X.Org X11 libXcursor runtime library.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 x11-libs/libXcursor < 1.1.15 >= 1.1.15
33
34 Description
35 ===========
36
37 It was discovered that libXcursor is prone to several heap overflows
38 when parsing malicious files.
39
40 Impact
41 ======
42
43 A remote attacker, by enticing a user to process a specially crafted
44 cursor file, could possibly execute arbitrary code with the privileges
45 of the process or cause a Denial of Service condition.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All LibXcursor users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot --verbose ">=x11-libs/libXcursor-1.1.15"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2017-16612
64 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-16612
65
66 Availability
67 ============
68
69 This GLSA and any updates to it are available for viewing at
70 the Gentoo Security Website:
71
72 https://security.gentoo.org/glsa/201801-04
73
74 Concerns?
75 =========
76
77 Security is a primary focus of Gentoo Linux and ensuring the
78 confidentiality and security of our users' machines is of utmost
79 importance to us. Any security concerns should be addressed to
80 security@g.o or alternatively, you may file a bug at
81 https://bugs.gentoo.org.
82
83 License
84 =======

Attachments

File name MIME type
signature.asc application/pgp-signature