Incorrect Permission Assignment for Critical Resource Affecting mesa package, versions <18.3.6-2+deb10u1
Snyk CVSS
Attack Complexity
Low
Threat Intelligence
EPSS
0.05% (21st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN10-MESA-481690
- published 10 Nov 2019
- disclosed 5 Nov 2019
Introduced: 5 Nov 2019
CVE-2019-5068 Open this link in a new tabHow to fix?
Upgrade Debian:10
mesa
to version 18.3.6-2+deb10u1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream mesa
package and not the mesa
package as distributed by Debian
.
See How to fix?
for Debian:10
relevant fixed versions and status.
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
References
- https://security-tracker.debian.org/tracker/CVE-2019-5068
- https://lists.debian.org/debian-lts-announce/2019/11/msg00013.html
- https://gitlab.freedesktop.org/mesa/mesa/-/commit/02c3dad0f3b4d26e0faa5cc51d06bc50d693dcdc
- https://lists.freedesktop.org/pipermail/mesa-dev/2019-October/223704.html
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00037.html
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0857
- https://usn.ubuntu.com/4271-1/
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2019-5068