You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa fontconfig

Sigurnosni nedostatak programskog paketa fontconfig

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3063-1
August 17, 2016

fontconfig vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

Fontconfig be made to crash or run programs if it opened a specially
crafted file.

Software Description:
– fontconfig: generic font configuration library

Details:

Tobias Stoeckmann discovered that Fontconfig incorrectly handled cache
files. A local attacker could possibly use this issue with a specially
crafted cache file to elevate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
fontconfig 2.11.94-0ubuntu1.1
libfontconfig1 2.11.94-0ubuntu1.1

Ubuntu 14.04 LTS:
fontconfig 2.11.0-0ubuntu4.2
libfontconfig1 2.11.0-0ubuntu4.2

Ubuntu 12.04 LTS:
fontconfig 2.8.0-3ubuntu9.2
libfontconfig1 2.8.0-3ubuntu9.2

After a standard system update you need to restart your session to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3063-1
CVE-2016-5384

Package Information:
https://launchpad.net/ubuntu/+source/fontconfig/2.11.94-0ubuntu1.1
https://launchpad.net/ubuntu/+source/fontconfig/2.11.0-0ubuntu4.2
https://launchpad.net/ubuntu/+source/fontconfig/2.8.0-3ubuntu9.2

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJXtJ4CAAoJEGVp2FWnRL6TZMIQAJC+83YwIe4m4qcC2cpbzFBE
7/SuMT7jL6WA/3tKu0/LkFNq5as7vwjOkQSkJRXj/LeRweYGJQJWdXC+TTwVMuqJ
7NHyh9fY2Hjkn7moxMNW9hPgOd+npb5ByCCLrBaqqigczy4wf4bFmem2OE/7sV7u
hGEvSwwXiB2JsFbI4wkT0KmLWBYO4CYXf9WN7ElaLD71nMwc3Sbw1XABDxcGKpcB
vhXvBhej27bV1sL+p+N3gcKM/UDmXhdOhftdqy2dVuVjgXvdAEu5hkCOJM5Il83C
hbK6lUVc1YBsN6E/sS9glo39VoIR+J6otUCQAxmN2g9izgBfPlddKsLHJlwn1nru
d4H+U5Jgte0Qo0lDMwBr5vbV68D7zkmYgqsHtNGaig445Z5rr4nHg+CszaC5nnNn
qkzQ3XzEi49W0s7y7iJ/6NWi9lxN/DvyC3vcms6pvXtJTHC8cZwQha6rsav+RwZs
QEG+KeEUvVpkPy35wHMQ4A7YIXveyYT1kUeM8kTB7JbO6FuQ+NJSp3epUATcFEwR
TssVhiKLsEJFPmGfiVBYbLpmve9F56/XHl95zmoxd4gJFHDjGz5iOEKi9BakgtKK
4gwF3AqGWODYs1A44AjWlDRDeQER/86yPDiTuVCsmu73fDSpMvqnH8d2SPMgSyfv
rGuDRsytzqd8vZlUS5wY
=qZpr
—–END PGP SIGNATURE—–

AutorMarko Stanec
Cert idNCERT-REF-2016-08-0116-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostatak programskih paketa mingw-xz i mingw-libarchive

Otkriveni su sigurnosni nedostaci u programskim paketima mingw-xz i mingw-libarchive za Fedoru. Otkriveni nedostatak posljedica je cjelobrojnog prepisivanja u biblioteki...

Close