USN-3362-1: X.Org X server vulnerabilities
24 July 2017
Several security issues were fixed in the X.Org X server.
Releases
Packages
- xorg-server - X.Org X11 server
- xorg-server-hwe-16.04 - X.Org X11 server
- xorg-server-lts-xenial - X.Org X11 server
Details
It was discovered that the X.Org X server incorrectly handled endianness
conversion of certain X events. An attacker able to connect to an X server,
either locally or remotely, could use this issue to crash the server, or
possibly execute arbitrary code as an administrator. (CVE-2017-10971)
It was discovered that the X.Org X server incorrectly handled endianness
conversion of certain X events. An attacker able to connect to an X server,
either locally or remotely, could use this issue to possibly obtain
sensitive information. (CVE-2017-10972)
Eric Sesterhenn discovered that the X.Org X server incorrectly compared
MIT cookies. An attacker could possibly use this issue to perform a timing
attack and recover the MIT cookie. (CVE-2017-2624)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 17.04
Ubuntu 16.04
Ubuntu 14.04
After a standard system update you need to reboot your computer to make
all the necessary changes.