/[advisories]/10569.adv
ViewVC logotype

Contents of /10569.adv

Parent Directory Parent Directory | Revision Log Revision Log


Revision 66 - (show annotations) (download)
Thu Jun 20 10:53:55 2013 UTC (10 years, 10 months ago) by boklm
File size: 1052 byte(s)
10569: Remove '2' listed twice
1 type: security
2 subject: Updated mesa packages fix multiple vulnerabilties
3 CVE:
4 - CVE-2013-1872
5 - CVE-2013-1993
6 src:
7 2:
8 core:
9 - mesa-8.0.5-1.1.mga2
10 tainted:
11 - mesa-8.0.5-1.1.mga2.tainted
12 description: |
13 Updated mesa packages fix security vulnerabilities:
14
15 An out-of-bounds access flaw was found in Mesa. If an application using
16 Mesa exposed the Mesa API to untrusted inputs (Mozilla Firefox does
17 this), an attacker could cause the application to crash or, potentially,
18 execute arbitrary code with the privileges of the user running the
19 application (CVE-2013-1872).
20
21 It was found that Mesa did not correctly validate messages from the X
22 server. A malicious X server could cause an application using Mesa to
23 crash or, potentially, execute arbitrary code with the privileges of the
24 user running the application (CVE-2013-1993).
25 references:
26 - http://www.x.org/wiki/Development/Security/Advisory-2013-05-23
27 - https://rhn.redhat.com/errata/RHSA-2013-0897.html
28 - https://bugs.mageia.org/show_bug.cgi?id=10569

  ViewVC Help
Powered by ViewVC 1.1.30