Rapid7 Vulnerability & Exploit Database

RHSA-2003:286: Updated XFree86 packages provide security and bug fixes

Back to Search

RHSA-2003:286: Updated XFree86 packages provide security and bug fixes

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
10/06/2003
Created
07/25/2018
Added
10/28/2005
Modified
07/04/2017

Description

Updated XFree86 packages for Red Hat Linux 7.1 and 7.2 provide security fixes to font libraries and XDM.

XFree86 is an implementation of the X Window System providing the core graphical user interface and video drivers in Red Hat Linux. XDM is the X display manager. Multiple integer overflows in the transfer and enumeration of font libraries in XFree86 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0730 to this issue. The risk to users from this vulnerability is limited because only clients can be affected by these bugs, however in some (non default) configurations, both xfs and the X Server can act as clients to remote font servers. XDM does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the pam_krb5 module. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0690 to this issue. Users are advised to upgrade to these updated XFree86 4.1.0 packages, which contain backported security patches and are not vulnerable to these issues.

Solution(s)

  • redhat-upgrade-xfree86
  • redhat-upgrade-xfree86-100dpi-fonts
  • redhat-upgrade-xfree86-75dpi-fonts
  • redhat-upgrade-xfree86-cyrillic-fonts
  • redhat-upgrade-xfree86-devel
  • redhat-upgrade-xfree86-doc
  • redhat-upgrade-xfree86-iso8859-15-100dpi-fonts
  • redhat-upgrade-xfree86-iso8859-15-75dpi-fonts
  • redhat-upgrade-xfree86-iso8859-2-100dpi-fonts
  • redhat-upgrade-xfree86-iso8859-2-75dpi-fonts
  • redhat-upgrade-xfree86-iso8859-9-100dpi-fonts
  • redhat-upgrade-xfree86-iso8859-9-75dpi-fonts
  • redhat-upgrade-xfree86-libs
  • redhat-upgrade-xfree86-tools
  • redhat-upgrade-xfree86-twm
  • redhat-upgrade-xfree86-xdm
  • redhat-upgrade-xfree86-xf86cfg
  • redhat-upgrade-xfree86-xfs
  • redhat-upgrade-xfree86-xnest
  • redhat-upgrade-xfree86-xvfb

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;