Oval Definition:oval:org.mitre.oval:def:8106
Revision Date:2014-06-23Version:22
Title:DSA-1466 xfree86 -- several vulnerabilities
Description:The X.org fix for CVE-2007-6429 introduced a regression in the MIT-SHM extension, which prevented the start of a few applications. This update provides updated packages for the xfree86 version included in Debian old stable (sarge) in addition to the fixed packages for Debian stable (etch), which were provided in DSA 1466-2. For reference the original advisory text below: Several local vulnerabilities have been discovered in the X.Org X server. The Common Vulnerabilities and Exposures project identifies the following problems: regenrecht discovered that missing input sanitising within the XFree86-Misc extension may lead to local privilege escalation. It was discovered that error messages of security policy file handling may lead to a minor information leak disclosing the existence of files otherwise inaccessible to the user. regenrecht discovered that missing input sanitising within the XInput-Misc extension may lead to local privilege escalation. regenrecht discovered that missing input sanitising within the TOG-CUP extension may lead to disclosure of memory contents. regenrecht discovered that integer overflows in the EVI and MIT-SHM extensions may lead to local privilege escalation. It was discovered that insufficient validation of PCF fonts could lead to local privilege escalation.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-5760
CVE-2007-5958
CVE-2007-6427
CVE-2007-6428
CVE-2007-6429
CVE-2008-0006
DSA-1466
Platform(s):Debian GNU/Linux 3.1
Debian GNU/Linux 4.0
Product(s):xfree86
Definition Synopsis
  • Release section
  • Debian GNU/Linux 4.0 is installed.
  • AND Packages section
  • xserver-xorg-core is earlier than 1.1.1-21etch2
  • OR libxfont1-dbg is earlier than 1.2.2-2.etch1
  • OR xdmx is earlier than 1.1.1-21etch2
  • OR xserver-xorg-dev is earlier than 1.1.1-21etch2
  • OR xvfb is earlier than 1.1.1-21etch2
  • OR xnest is earlier than 1.1.1-21etch2
  • OR libxfont1 is earlier than 1.2.2-2.etch1
  • OR xserver-xephyr is earlier than 1.1.1-21etch2
  • OR libxfont-dev is earlier than 1.2.2-2.etch1
  • OR xdmx-tools is earlier than 1.1.1-21etch2
  • OR Release section
  • Debian GNU/Linux 3.1 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • xfree86-common is earlier than 4.3.0.dfsg.1-14sarge7
  • OR pm-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR x-window-system is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibs-data is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfonts-100dpi is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfonts-base is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xspecs is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfonts-scalable is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfonts-75dpi is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibs-pic is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfonts-cyrillic is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibs is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa3-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibs-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfonts-100dpi-transcoded is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfonts-base-transcoded is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibs-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfonts-75dpi-transcoded is earlier than 4.3.0.dfsg.1-14sarge7
  • OR x-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • libxtrap-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxtst6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libdps1-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR lbxproxy is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxext6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxi-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxt-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa3 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxv-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxmuu-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-gl-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxv1 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfs is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libice6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libsm6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxtrap6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxaw6-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxtrap6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxaw6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xbase-clients is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xfwp is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xmh is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxpm4 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxmu6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-gl is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libice6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR twm is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xutils is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxpm-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxi6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxaw7-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxrandr2-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxmuu1-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR proxymngr is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-glu-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libx11-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xserver-common is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libx11-6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxrandr2 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibs-static-pic is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxext-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libice-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxaw7 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxft1 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xdm is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xterm is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxext6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libx11-6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxmu6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxaw7-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libdps-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libsm6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-glu is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxmuu1 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxmu-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxaw6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxt6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxt6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR x-window-system-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxp6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxp-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibs-static-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxpm4-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xvfb is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxtst-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxp6 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-gl-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xnest is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxv1-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libdps1 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxft1-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxtst6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxi6-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libxrandr-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-glu-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR libsm-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR x-window-system-core is earlier than 4.3.0.dfsg.1-14sarge7
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • AND Packages section
  • xlibosmesa-dev is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-dri is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibosmesa4 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xserver-xfree86 is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibmesa-dri-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xserver-xfree86-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xlibosmesa4-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR Supported platform section
  • Installed architecture is arm
  • AND Packages section
  • xserver-xfree86-dbg is earlier than 4.3.0.dfsg.1-14sarge7
  • OR xserver-xfree86 is earlier than 4.3.0.dfsg.1-14sarge7
  • BACK