Oval Definition:oval:com.redhat.rhsa:def:20040061
Revision Date:2004-02-16Version:502
Title:RHSA-2004:061: XFree86 security update (Important)
Description:XFree86 is an implementation of the X Window System, providing the core graphical user interface and video drivers.

iDefense discovered two buffer overflows in the parsing of the 'font.alias' file. A local attacker could exploit this vulnerability by creating a carefully-crafted file and gaining root privileges. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0083 and CAN-2004-0084 to these issues.

Additionally David Dawes discovered additional flaws in reading font files. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0106 to these issues.

All users of XFree86 are advised to upgrade to these erratum packages, which contain a backported fix and are not vulnerable to these issues.

Red Hat would like to thank David Dawes from XFree86 for the patches and notification of these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0083
CVE-2004-0084
CVE-2004-0106
RHSA-2004:061-01
Platform(s):Red Hat Enterprise Linux 3
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 3 is installed
  • AND Package Information
  • XFree86-xdm is earlier than 0:4.3.0-55.EL
  • AND XFree86-xdm is signed with Red Hat master key
  • OR
  • XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-libs-data is earlier than 0:4.3.0-55.EL
  • AND XFree86-libs-data is signed with Red Hat master key
  • OR
  • XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-doc is earlier than 0:4.3.0-55.EL
  • AND XFree86-doc is signed with Red Hat master key
  • OR
  • XFree86-cyrillic-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-cyrillic-fonts is signed with Red Hat master key
  • OR
  • XFree86 is earlier than 0:4.3.0-55.EL
  • AND XFree86 is signed with Red Hat master key
  • OR
  • XFree86-truetype-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-truetype-fonts is signed with Red Hat master key
  • OR
  • XFree86-Mesa-libGL is earlier than 0:4.3.0-55.EL
  • AND XFree86-Mesa-libGL is signed with Red Hat master key
  • OR
  • XFree86-libs is earlier than 0:4.3.0-55.EL
  • AND XFree86-libs is signed with Red Hat master key
  • OR
  • XFree86-xfs is earlier than 0:4.3.0-55.EL
  • AND XFree86-xfs is signed with Red Hat master key
  • OR
  • XFree86-75dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-75dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-Xnest is earlier than 0:4.3.0-55.EL
  • AND XFree86-Xnest is signed with Red Hat master key
  • OR
  • XFree86-syriac-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-syriac-fonts is signed with Red Hat master key
  • OR
  • XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-Mesa-libGLU is earlier than 0:4.3.0-55.EL
  • AND XFree86-Mesa-libGLU is signed with Red Hat master key
  • OR
  • XFree86-100dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-100dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key
  • OR
  • XFree86-font-utils is earlier than 0:4.3.0-55.EL
  • AND XFree86-font-utils is signed with Red Hat master key
  • OR
  • XFree86-base-fonts is earlier than 0:4.3.0-55.EL
  • AND XFree86-base-fonts is signed with Red Hat master key
  • OR
  • XFree86-Xvfb is earlier than 0:4.3.0-55.EL
  • AND XFree86-Xvfb is signed with Red Hat master key
  • OR
  • XFree86-twm is earlier than 0:4.3.0-55.EL
  • AND XFree86-twm is signed with Red Hat master key
  • OR
  • XFree86-tools is earlier than 0:4.3.0-55.EL
  • AND XFree86-tools is signed with Red Hat master key
  • OR
  • XFree86-xauth is earlier than 0:4.3.0-55.EL
  • AND XFree86-xauth is signed with Red Hat master key
  • OR
  • XFree86-devel is earlier than 0:4.3.0-55.EL
  • AND XFree86-devel is signed with Red Hat master key
  • BACK