Rapid7 Vulnerability & Exploit Database

CESA-2004:061: XFree86 security update

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

CESA-2004:061: XFree86 security update

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
03/03/2004
Created
07/25/2018
Added
03/12/2010
Modified
07/04/2017

Description

Updated XFree86 packages that fix a privilege escalation vulnerability are now available. [Update 16 February 2004] Erratum filelist has been modified for x86_64 and s390x only so that the correct multi-lib packages are available.

XFree86 is an implementation of the X Window System, providing the core graphical user interface and video drivers. iDefense discovered two buffer overflows in the parsing of the 'font.alias' file. A local attacker could exploit this vulnerability by creating a carefully-crafted file and gaining root privileges. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0083 and CAN-2004-0084 to these issues. Additionally David Dawes discovered additional flaws in reading font files. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0106 to these issues. All users of XFree86 are advised to upgrade to these erratum packages, which contain a backported fix and are not vulnerable to these issues. CentOS would like to thank David Dawes from XFree86 for the patches and notification of these issues.

Solution(s)

  • centos-upgrade-xfree86
  • centos-upgrade-xfree86-100dpi-fonts
  • centos-upgrade-xfree86-75dpi-fonts
  • centos-upgrade-xfree86-base-fonts
  • centos-upgrade-xfree86-cyrillic-fonts
  • centos-upgrade-xfree86-devel
  • centos-upgrade-xfree86-doc
  • centos-upgrade-xfree86-font-utils
  • centos-upgrade-xfree86-iso8859-14-100dpi-fonts
  • centos-upgrade-xfree86-iso8859-14-75dpi-fonts
  • centos-upgrade-xfree86-iso8859-15-100dpi-fonts
  • centos-upgrade-xfree86-iso8859-15-75dpi-fonts
  • centos-upgrade-xfree86-iso8859-2-100dpi-fonts
  • centos-upgrade-xfree86-iso8859-2-75dpi-fonts
  • centos-upgrade-xfree86-iso8859-9-100dpi-fonts
  • centos-upgrade-xfree86-iso8859-9-75dpi-fonts
  • centos-upgrade-xfree86-libs
  • centos-upgrade-xfree86-libs-data
  • centos-upgrade-xfree86-mesa-libgl
  • centos-upgrade-xfree86-mesa-libglu
  • centos-upgrade-xfree86-syriac-fonts
  • centos-upgrade-xfree86-tools
  • centos-upgrade-xfree86-truetype-fonts
  • centos-upgrade-xfree86-twm
  • centos-upgrade-xfree86-xauth
  • centos-upgrade-xfree86-xdm
  • centos-upgrade-xfree86-xfs
  • centos-upgrade-xfree86-xnest
  • centos-upgrade-xfree86-xvfb

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;