Oval Definition:oval:com.redhat.rhsa:def:20111154
Revision Date:2011-08-11Version:636
Title:RHSA-2011:1154: libXfont security update (Important)
Description:The libXfont packages provide the X.Org libXfont runtime library. X.Org is an open source implementation of the X Window System.

  • A buffer overflow flaw was found in the way the libXfont library, used by the X.Org server, handled malformed font files compressed using UNIX compress. A malicious, local user could exploit this issue to potentially execute arbitrary code with the privileges of the X.Org server. (CVE-2011-2895)

    Users of libXfont should upgrade to these updated packages, which contain a backported patch to resolve this issue. All running X.Org server instances must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-2895
    CVE-2011-2895
    RHSA-2011:1154
    RHSA-2011:1154-01
    RHSA-2011:1154-01
    Platform(s):Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • libXfont is earlier than 0:1.4.1-2.el6_1
  • AND libXfont is signed with Red Hat redhatrelease2 key
  • libXfont-devel is earlier than 0:1.4.1-2.el6_1
  • AND libXfont-devel is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • libXfont is earlier than 0:1.2.2-1.0.4.el5_7
  • AND libXfont is signed with Red Hat redhatrelease2 key
  • libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7
  • AND libXfont-devel is signed with Red Hat redhatrelease2 key
  • BACK