Rapid7 Vulnerability & Exploit Database

RHSA-2003:289: XFree86 security update

Back to Search

RHSA-2003:289: XFree86 security update

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
10/06/2003
Created
07/25/2018
Added
10/28/2005
Modified
07/12/2017

Description

Updated XFree86 packages provide security fixes to font libraries and XDM.

XFree86 is an implementation of the X Window System providing the core graphical user interface and video drivers. XDM is the X display manager. Multiple integer overflows in the transfer and enumeration of font libraries in XFree86 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0730 to this issue. The risk to users from this vulnerability is limited because only clients can be affected by these bugs, however in some (non-default) configurations, both xfs and the X Server can act as clients to remote font servers. XDM does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the pam_krb5 module. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0690 to this issue. Users are advised to upgrade to these updated XFree86 4.1.0 packages, which contain backported security patches and are not vulnerable to these issues.

Solution(s)

  • redhat-upgrade-xfree86
  • redhat-upgrade-xfree86-100dpi-fonts
  • redhat-upgrade-xfree86-75dpi-fonts
  • redhat-upgrade-xfree86-cyrillic-fonts
  • redhat-upgrade-xfree86-devel
  • redhat-upgrade-xfree86-doc
  • redhat-upgrade-xfree86-iso8859-15-100dpi-fonts
  • redhat-upgrade-xfree86-iso8859-15-75dpi-fonts
  • redhat-upgrade-xfree86-iso8859-2-100dpi-fonts
  • redhat-upgrade-xfree86-iso8859-2-75dpi-fonts
  • redhat-upgrade-xfree86-iso8859-9-100dpi-fonts
  • redhat-upgrade-xfree86-iso8859-9-75dpi-fonts
  • redhat-upgrade-xfree86-libs
  • redhat-upgrade-xfree86-tools
  • redhat-upgrade-xfree86-twm
  • redhat-upgrade-xfree86-xdm
  • redhat-upgrade-xfree86-xf86cfg
  • redhat-upgrade-xfree86-xfs
  • redhat-upgrade-xfree86-xnest
  • redhat-upgrade-xfree86-xvfb

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;