Important CentOS mesa Update

Metadata

medium
6.8
glx-utils-9.0-0.8.el6_4.3.i686.rpm, glx-utils-9.0-0.8.el6_4.3.x86_64.rpm, mesa-9.0-0.8.el6_4.3.src.rpm, mesa-demos-9.0-0.8.el6_4.3.i686.rpm, mesa-demos-9.0-0.8.el6_4.3.x86_64.rpm, mesa-dri-drivers-9.0-0.8.el6_4.3.i686.rpm, mesa-dri-drivers-9.0-0.8.el6_4.3.x86_64.rpm, mesa-dri-filesystem-9.0-0.8.el6_4.3.i686.rpm, mesa-dri-filesystem-9.0-0.8.el6_4.3.x86_64.rpm, mesa-libGL-9.0-0.8.el6_4.3.i686.rpm, mesa-libGL-9.0-0.8.el6_4.3.x86_64.rpm, mesa-libGL-devel-9.0-0.8.el6_4.3.i686.rpm, mesa-libGL-devel-9.0-0.8.el6_4.3.x86_64.rpm, mesa-libGLU-9.0-0.8.el6_4.3.i686.rpm, mesa-libGLU-9.0-0.8.el6_4.3.x86_64.rpm, mesa-libGLU-devel-9.0-0.8.el6_4.3.i686.rpm, mesa-libGLU-devel-9.0-0.8.el6_4.3.x86_64.rpm, mesa-libOSMesa-9.0-0.8.el6_4.3.i686.rpm, mesa-libOSMesa-9.0-0.8.el6_4.3.x86_64.rpm, mesa-libOSMesa-devel-9.0-0.8.el6_4.3.i686.rpm, mesa-libOSMesa-devel-9.0-0.8.el6_4.3.x86_64.rpm
CVE-2013-1872, CVE-2013-1993
rhn.redhat.com, lists.centos.org
2013-06-03
2017-07-27 19:05
ALAS-2013-198
Moderate CentOS mesa Update
CVE-2013-1872 mesa
CVE-2013-1993 mesa
CVE-2013-1993
CVE-2013-1872
2017-04-01 19:07
2017-01-05 20:11

Description


Updated mesa packages that fix multiple security issues are now available
for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having
important security impact. Common Vulnerability Scoring System (CVSS) base
scores, which give detailed severity ratings, are available for each
vulnerability from the CVE links in the References section.

Mesa provides a 3D graphics API that is compatible with Open Graphics
Library (OpenGL). It also provides hardware-accelerated drivers for many
popular graphics chips.

An out-of-bounds access flaw was found in Mesa. If an application using
Mesa exposed the Mesa API to untrusted inputs (Mozilla Firefox does
this), an attacker could cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2013-1872)

It was found that Mesa did not correctly validate messages from the X
server. A malicious X server could cause an application using Mesa to crash
or, potentially, execute arbitrary code with the privileges of the user
running the application. (CVE-2013-1993)

All users of Mesa are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications linked against Mesa must be restarted for this update to take
effect.
Please see https://www.redhat.com/footer/terms-of-use.html

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

Release Package Patched in
6 glx-utils glx-utils-9.0-0.8.el6_4.3.i686.rpm
glx-utils glx-utils-9.0-0.8.el6_4.3.x86_64.rpm
mesa mesa-9.0-0.8.el6_4.3.src.rpm
mesa-demos mesa-demos-9.0-0.8.el6_4.3.i686.rpm
mesa-demos mesa-demos-9.0-0.8.el6_4.3.x86_64.rpm
mesa-dri-drivers mesa-dri-drivers-9.0-0.8.el6_4.3.i686.rpm
mesa-dri-drivers mesa-dri-drivers-9.0-0.8.el6_4.3.x86_64.rpm
mesa-dri-filesystem mesa-dri-filesystem-9.0-0.8.el6_4.3.i686.rpm
mesa-dri-filesystem mesa-dri-filesystem-9.0-0.8.el6_4.3.x86_64.rpm
mesa-libGL mesa-libGL-9.0-0.8.el6_4.3.i686.rpm
mesa-libGL mesa-libGL-9.0-0.8.el6_4.3.x86_64.rpm
mesa-libGL-devel mesa-libGL-devel-9.0-0.8.el6_4.3.i686.rpm
mesa-libGL-devel mesa-libGL-devel-9.0-0.8.el6_4.3.x86_64.rpm
mesa-libGLU mesa-libGLU-9.0-0.8.el6_4.3.i686.rpm
mesa-libGLU mesa-libGLU-9.0-0.8.el6_4.3.x86_64.rpm
mesa-libGLU-devel mesa-libGLU-devel-9.0-0.8.el6_4.3.i686.rpm
mesa-libGLU-devel mesa-libGLU-devel-9.0-0.8.el6_4.3.x86_64.rpm
mesa-libOSMesa mesa-libOSMesa-9.0-0.8.el6_4.3.i686.rpm
mesa-libOSMesa mesa-libOSMesa-9.0-0.8.el6_4.3.x86_64.rpm
mesa-libOSMesa-devel mesa-libOSMesa-devel-9.0-0.8.el6_4.3.i686.rpm
mesa-libOSMesa-devel mesa-libOSMesa-devel-9.0-0.8.el6_4.3.x86_64.rpm