PT-2003-2522 · Xfree86+1 · Xfree86-Xauth+20

Stephan Kulow

·

Publicado

1970-01-01

·

Atualizado

2017-10-11

·

CVE-2003-0690

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFree86-xf86cfg versions 4.1.0 through 4.2.1 XFree86-base-fonts versions 4.2.1 through 4.3.0 XFree86-font-utils versions 4.2.1 through 4.3.0 XFree86 versions 4.1.0 through 4.3.0 XFree86-Mesa-libGL versions 4.2.1 through 4.3.0 XFree86-ISO8859-9-75dpi-fonts versions 4.1.0 through 4.3.0 kdebase-devel version 3.0.5a XFree86-sdk version 4.3.0 XFree86-tools versions 4.1.0 through 4.3.0 XFree86-devel versions 4.1.0 through 4.3.0 XFree86-doc versions 4.1.0 through 4.3.0 XFree86-ISO8859-15-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-2-100dpi-fonts versions 4.1.0 through 4.3.0 XFree86-xauth versions 4.2.1 through 4.3.0 XFree86-ISO8859-15-75dpi-fonts versions 4.1.0 through 4.3.0 XFree86-ISO8859-9-100dpi-fonts versions 4.1.0 through 4.3.0 xlibosmesa3 xfonts-pex xlib6g xlib6g-dev
Description The issue is related to multiple vulnerabilities in various packages of the XFree86 and KDE software, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. In the case of KDM in KDE 3.1.3 and earlier, the pam setcred function call is not verified, potentially allowing attackers to gain root privileges under certain conditions.
Recommendations For XFree86-xf86cfg version 4.2.1, update to a newer version. For XFree86-base-fonts version 4.3.0, update to a newer version. For XFree86-font-utils version 4.3.0, update to a newer version. For XFree86 version 4.3.0, update to a newer version. For XFree86-Mesa-libGL version 4.3.0, update to a newer version. For XFree86-ISO8859-9-75dpi-fonts version 4.3.0, update to a newer version. For kdebase-devel version 3.0.5a, update to a newer version. For XFree86-sdk version 4.3.0, update to a newer version. For XFree86-tools version 4.3.0, update to a newer version. For XFree86-devel version 4.3.0, update to a newer version. For XFree86-doc version 4.3.0, update to a newer version. For XFree86-ISO8859-15-100dpi-fonts version 4.3.0, update to a newer version. For XFree86-100dpi-fonts version 4.3.0, update to a newer version. For XFree86-ISO8859-2-100dpi-fonts version 4.3.0, update to a newer version. For XFree86-xauth version 4.3.0, update to a newer version. For XFree86-ISO8859-15-75dpi-fonts version 4.3.0, update to a newer version. For XFree86-ISO8859-9-100dpi-fonts version 4.3.0, update to a newer version. For xlibosmesa3, update to a newer version. For xfonts-pex, update to a newer version. For xlib6g, update to a newer version. For xlib6g-dev, update to a newer version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-01798
BDU:2015-01799
BDU:2015-01800
BDU:2015-01801
BDU:2015-01802
BDU:2015-08028
BDU:2015-08030
BDU:2015-08031
BDU:2015-08032
BDU:2015-08248
BDU:2015-08249
BDU:2015-08250
BDU:2015-08251
BDU:2015-08252
BDU:2015-08253
BDU:2015-08254
BDU:2015-08255
BDU:2015-08256
BDU:2015-08257
BDU:2015-08258
BDU:2015-08259
BDU:2015-08261
BDU:2015-08262
BDU:2015-08263
BDU:2015-08264
BDU:2015-08265
BDU:2015-08266
BDU:2015-08267
BDU:2015-08268
BDU:2015-08269
BDU:2015-08270
BDU:2015-08271
BDU:2015-08272
BDU:2015-08273
BDU:2015-08274
BDU:2015-08276
BDU:2015-08277
BDU:2015-08278
BDU:2015-08279
BDU:2015-08280
BDU:2015-08281
BDU:2015-08282
BDU:2015-08283
BDU:2015-08284
BDU:2015-08285
BDU:2015-08286
BDU:2015-08287
BDU:2015-08288
BDU:2015-08289
BDU:2015-08290
BDU:2015-08291
BDU:2015-08317
BDU:2015-08318
BDU:2015-08319
BDU:2015-08320
BDU:2015-08321
BDU:2015-08322
BDU:2015-08323
BDU:2015-08324
BDU:2015-08325
BDU:2015-08326
BDU:2015-08327
BDU:2015-08328
BDU:2015-08329
BDU:2015-08330
BDU:2015-08331
BDU:2015-08332
BDU:2015-08333
BDU:2015-08334
BDU:2015-08335
BDU:2015-08336
BDU:2015-08337
BDU:2015-08338
BDU:2015-08339
BDU:2015-08340
BDU:2015-08341
BDU:2015-08342
BDU:2015-08343
BDU:2015-08344
BDU:2015-08345
BDU:2015-08346
BDU:2015-08347
BDU:2015-08348
BDU:2015-08349
BDU:2015-08350
CVE-2003-0690
DSA-388
DSA-443

Produtos afetados

Xfree86
Xfree86-100Dpi-Fonts
Xfree86-Iso8859-15-100Dpi-Fonts
Xfree86-Iso8859-15-75Dpi-Fonts
Xfree86-Iso8859-2-100Dpi-Fonts
Xfree86-Iso8859-9-100Dpi-Fonts
Xfree86-Iso8859-9-75Dpi-Fonts
Xfree86-Mesa-Libgl
Xfree86-Base-Fonts
Xfree86-Devel
Xfree86-Doc
Xfree86-Font-Utils
Xfree86-Sdk
Xfree86-Tools
Xfree86-Xauth
Xfree86-Xf86Cfg
Kdebase-Devel
Xfonts-Pex
Xlib6G
Xlib6G-Dev
Xlibosmesa3