Advisories Blog | G5 Cyber Security

Ubuntu Security Notice 939-1

Ubuntu Security Notice 939-1 – L. Minier discovered that xvfb-run did not correctly keep the X.org session cookie private. A local attacker could gain access to any local sessions started by xvfb-run. Ubuntu 9.10 was not affected. It was discovered that the X.org server did not correctly handle certain calculations. A remote attacker could exploit this to crash the X.org session or possibly run arbitrary code with root privileges.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/89686/USN-939-1.txt

Source: https://packetstormsecurity.com/files/89686/Ubuntu-Security-Notice-939-1.html

Exit mobile version