Oval Definition:oval:com.redhat.rhsa:def:20110433
Revision Date:2011-04-11Version:638
Title:RHSA-2011:0433: xorg-x11-server-utils security update (Moderate)
Description:The xorg-x11-server-utils package contains a collection of utilities used to modify and query the runtime configuration of the X.Org server. X.Org is an open source implementation of the X Window System.

  • A flaw was found in the X.Org X server resource database utility, xrdb. Certain variables were not properly sanitized during the launch of a user's graphical session, which could possibly allow a remote attacker to execute arbitrary code with root privileges, if they were able to make the display manager execute xrdb with a specially-crafted X client hostname. For example, by configuring the hostname on the target system via a crafted DHCP reply, or by using the X Display Manager Control Protocol (XDMCP) to connect to that system from a host that has a special DNS name. (CVE-2011-0465)

    Red Hat would like to thank Matthieu Herrb for reporting this issue. Upstream acknowledges Sebastian Krahmer of the SuSE Security Team as the original reporter.

    Users of xorg-x11-server-utils should upgrade to this updated package, which contains a backported patch to resolve this issue. All running X.Org server instances must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-0465
    CVE-2011-0465
    RHSA-2011:0433
    RHSA-2011:0433-01
    RHSA-2011:0433-01
    Platform(s):Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND xorg-x11-server-utils is earlier than 0:7.4-15.el6_0.1
  • AND xorg-x11-server-utils is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND xorg-x11-server-utils is earlier than 0:7.1-5.el5_6.1
  • AND xorg-x11-server-utils is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • xorg-x11-server-utils is earlier than 0:7.4-15.el6_0.1
  • AND xorg-x11-server-utils is signed with Red Hat redhatrelease2 key
  • AND Package Information
  • Red Hat Enterprise Linux 6 Client is installed
  • OR Red Hat Enterprise Linux 6 Server is installed
  • OR Red Hat Enterprise Linux 6 Workstation is installed
  • OR Red Hat Enterprise Linux 6 ComputeNode is installed
  • BACK