Oval Definition:oval:org.mitre.oval:def:27049
Revision Date:2014-12-08Version:10
Title:RHSA-2013:1620 -- xorg-x11-server security and bug fix update (Low)
Description:X.Org is an open source implementation of the X Window System. It providesthe basic low-level functionality that full-fledged graphical userinterfaces are designed upon.A flaw was found in the way the X.org X11 server registered new hot pluggeddevices. If a local user switched to a different session and plugged in anew device, input from that device could become available in the previoussession, possibly leading to information disclosure. (CVE-2013-1940)This issue was found by David Airlie and Peter Hutterer of Red Hat.This update also fixes the following bugs:* A previous upstream patch modified the Xephyr X server to be resizeable,however, it did not enable the resize functionality by default. As aconsequence, X sandboxes were not resizeable on Red Hat Enterprise Linux6.4 and later. This update enables the resize functionality by default sothat X sandboxes can now be resized as expected. (BZ#915202)* In Red Hat Enterprise Linux 6, the X Security extension (XC-SECURITY)has been disabled and replaced by X Access Control Extension (XACE).However, XACE does not yet include functionality that was previouslyavailable in XC-SECURITY. With this update, XC-SECURITY is enabled in thexorg-x11-server spec file on Red Hat Enterprise Linux 6. (BZ#957298)* Upstream code changes to extension initialization accidentally disabledthe GLX extension in Xvfb (the X virtual frame buffer), rendering headless3D applications not functional. An upstream patch to this problem has beenbackported so the GLX extension is enabled again, and applications relyingon this extension work as expected. (BZ#969538)All xorg-x11-server users are advised to upgrade to these updated packages,which contain backported patches to correct these issues.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2013:1620
CVE-2013-1940
RHSA-2013:1620
Platform(s):CentOS Linux 6
Red Hat Enterprise Linux 6
Product(s):xorg-x11-server
Definition Synopsis
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND Packages match section
  • xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.el6
  • OR xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.el6
  • OR xorg-x11-server-Xnest is earlier than 0:1.13.0-23.el6
  • OR xorg-x11-server-Xorg is earlier than 0:1.13.0-23.el6
  • OR xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.el6
  • OR xorg-x11-server-common is earlier than 0:1.13.0-23.el6
  • OR xorg-x11-server-debuginfo is earlier than 0:1.13.0-23.el6
  • OR xorg-x11-server-devel is earlier than 0:1.13.0-23.el6
  • OR xorg-x11-server-source is earlier than 0:1.13.0-23.el6
  • CentOS Linux 6 release section
  • The operating system installed on the system is CentOS Linux 6.x
  • AND Packages match section
  • xorg-x11-server-common is earlier than 0:1.13.0-23.el6.centos
  • OR xorg-x11-server-devel is earlier than 0:1.13.0-23.el6.centos
  • OR xorg-x11-server-source is earlier than 0:1.13.0-23.el6.centos
  • OR xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.el6.centos
  • OR xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.el6.centos
  • OR xorg-x11-server-Xnest is earlier than 0:1.13.0-23.el6.centos
  • OR xorg-x11-server-Xorg is earlier than 0:1.13.0-23.el6.centos
  • OR xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.el6.centos
  • BACK