Rapid7 Vulnerability & Exploit Database

Ubuntu: USN-4271-1 (CVE-2019-5068): Mesa vulnerability

Back to Search

Ubuntu: USN-4271-1 (CVE-2019-5068): Mesa vulnerability

Severity
4
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:N)
Published
11/05/2019
Created
02/11/2020
Added
02/07/2020
Modified
02/07/2020

Description

An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.

Solution(s)

  • ubuntu-upgrade-libd3dadapter9-mesa
  • ubuntu-upgrade-libegl-mesa0
  • ubuntu-upgrade-libegl1-mesa
  • ubuntu-upgrade-libgbm1
  • ubuntu-upgrade-libgl1-mesa-dri
  • ubuntu-upgrade-libgl1-mesa-glx
  • ubuntu-upgrade-libglapi-mesa
  • ubuntu-upgrade-libgles2-mesa
  • ubuntu-upgrade-libglx-mesa0
  • ubuntu-upgrade-libosmesa6
  • ubuntu-upgrade-libwayland-egl1-mesa
  • ubuntu-upgrade-libxatracker2
  • ubuntu-upgrade-mesa-opencl-icd
  • ubuntu-upgrade-mesa-va-drivers
  • ubuntu-upgrade-mesa-vdpau-drivers
  • ubuntu-upgrade-mesa-vulkan-drivers

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;