Rapid7 Vulnerability & Exploit Database

CESA-2004:152: XFree86 security update

Free InsightVM Trial No credit card necessary
Watch Demo See how it all works
Back to Search

CESA-2004:152: XFree86 security update

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
03/15/2004
Created
07/25/2018
Added
03/12/2010
Modified
07/04/2017

Description

Updated XFree86 packages that fix a minor denial of service vulnerability are now available.

XFree86 is an implementation of the X Window System, providing the core graphical user interface and video drivers. Flaws in XFree86 4.1.0 allows local or remote attackers who are able to connect to the X server to cause a denial of service via an out-of-bounds array index or integer signedness error when using the GLX extension and Direct Rendering Infrastructure (DRI). The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0093 and CAN-2004-0094 to these issues. These issues do not affect CentOS Linux 3. All users of XFree86 are advised to upgrade to these erratum packages, which contain a backported fix and are not vulnerable to these issues.

Solution(s)

  • centos-upgrade-xfree86
  • centos-upgrade-xfree86-100dpi-fonts
  • centos-upgrade-xfree86-75dpi-fonts
  • centos-upgrade-xfree86-cyrillic-fonts
  • centos-upgrade-xfree86-devel
  • centos-upgrade-xfree86-doc
  • centos-upgrade-xfree86-iso8859-15-100dpi-fonts
  • centos-upgrade-xfree86-iso8859-15-75dpi-fonts
  • centos-upgrade-xfree86-iso8859-2-100dpi-fonts
  • centos-upgrade-xfree86-iso8859-2-75dpi-fonts
  • centos-upgrade-xfree86-iso8859-9-100dpi-fonts
  • centos-upgrade-xfree86-iso8859-9-75dpi-fonts
  • centos-upgrade-xfree86-libs
  • centos-upgrade-xfree86-tools
  • centos-upgrade-xfree86-twm
  • centos-upgrade-xfree86-xdm
  • centos-upgrade-xfree86-xf86cfg
  • centos-upgrade-xfree86-xfs
  • centos-upgrade-xfree86-xnest
  • centos-upgrade-xfree86-xvfb

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;