PT-2003-1088 · Red Hat+2 · Red Hat+3

George Lebl

·

Published

2003-08-11

·

Updated

2017-10-11

·

CVE-2003-0692

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFree86-base-fonts versions 4.3.0 XFree86 versions 4.3.0 kdebase-devel versions 3.0.5a XFree86-sdk versions 4.3.0 XFree86-100dpi-fonts versions 4.3.0 kdebase versions 3.0.5a, 2.2.2 XFree86-twm versions 4.3.0 XFree86-ISO8859-2-100dpi-fonts versions 4.3.0 XFree86-75dpi-fonts versions 4.3.0 XFree86-ISO8859-9-100dpi-fonts versions 4.3.0 XFree86-devel versions 4.3.0 XFree86-truetype-fonts versions 4.3.0 XFree86-Mesa-libGLU versions 4.3.0 XFree86-Xvfb versions 4.3.0 XFree86-syriac-fonts versions 4.3.0 XFree86-Mesa-libGL versions 4.3.0 XFree86-ISO8859-14-100dpi-fonts versions 4.3.0 XFree86-ISO8859-14-75dpi-fonts versions 4.3.0 XFree86-ISO8859-9-75dpi-fonts versions 4.3.0 XFree86-ISO8859-15-75dpi-fonts versions 4.3.0 XFree86-xdm versions 4.3.0 XFree86-tools versions 4.3.0 XFree86-doc versions 4.3.0 XFree86-ISO8859-15-100dpi-fonts versions 4.3.0 XFree86-libs versions 4.3.0 XFree86-Xnest versions 4.3.0 XFree86-xfs versions 4.3.0 XFree86-xauth versions 4.3.0 XFree86-libs-data versions 4.3.0 XFree86-ISO8859-2-75dpi-fonts versions 4.3.0 XFree86-cyrillic-fonts versions 4.3.0 kdebase-devel versions 2.2.2 XFree86-font-utils versions 4.3.0
Description The issue affects multiple packages of the Red Hat Linux operating system, including XFree86 and KDE components. Exploitation of these vulnerabilities can lead to a breach of confidentiality, integrity, and availability of protected information. The vulnerabilities can be exploited remotely. In the case of KDM in KDE 3.1.3 and earlier, a weak session cookie generation algorithm is used, which does not provide 128 bits of entropy, allowing attackers to guess session cookies via brute force methods and gain access to the user session.
Recommendations For XFree86-base-fonts version 4.3.0, update to a newer version. For XFree86 version 4.3.0, update to a newer version. For kdebase-devel version 3.0.5a, update to a newer version. For XFree86-sdk version 4.3.0, update to a newer version. For XFree86-100dpi-fonts version 4.3.0, update to a newer version. For kdebase versions 3.0.5a and 2.2.2, update to a newer version. For XFree86-twm version 4.3.0, update to a newer version. For XFree86-ISO8859-2-100dpi-fonts version 4.3.0, update to a newer version. For XFree86-75dpi-fonts version 4.3.0, update to a newer version. For XFree86-ISO8859-9-100dpi-fonts version 4.3.0, update to a newer version. For XFree86-devel version 4.3.0, update to a newer version. For XFree86-truetype-fonts version 4.3.0, update to a newer version. For XFree86-Mesa-libGLU version 4.3.0, update to a newer version. For XFree86-Xvfb version 4.3.0, update to a newer version. For XFree86-syriac-fonts version 4.3.0, update to a newer version. For XFree86-Mesa-libGL version 4.3.0, update to a newer version. For XFree86-ISO8859-14-100dpi-fonts version 4.3.0, update to a newer version. For XFree86-ISO8859-14-75dpi-fonts version 4.3.0, update to a newer version. For XFree86-ISO8859-9-75dpi-fonts version 4.3.0, update to a newer version. For XFree86-ISO8859-15-75dpi-fonts version 4.3.0, update to a newer version. For XFree86-xdm version 4.3.0, update to a newer version. For XFree86-tools version 4.3.0, update to a newer version. For XFree86-doc version 4.3.0, update to a newer version. For XFree86-ISO8859-15-100dpi-fonts version 4.3.0, update to a newer version. For XFree86-libs version 4.3.0, update to a newer version. For XFree86-Xnest version 4.3.0, update to a newer version. For XFree86-xfs version 4.3.0, update to a newer version. For XFree86-xauth version 4.3.0, update to a newer version. For XFree86-libs-data version 4.3.0, update to a newer version. For XFree86-ISO8859-2-75dpi-fonts version 4.3.0, update to a newer version. For XFree86-cyrillic-fonts version 4.3.0, update to a newer version. For kdebase-devel version 2.2.2, update to a newer version. For XFree86-font-utils version 4.3.0, update to a newer version. As a temporary workaround, consider disabling the weak session cookie generation algorithm in KDM until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08028
BDU:2015-08030
BDU:2015-08031
BDU:2015-08032
BDU:2015-08321
BDU:2015-08322
BDU:2015-08323
BDU:2015-08324
BDU:2015-08325
BDU:2015-08326
BDU:2015-08327
BDU:2015-08328
BDU:2015-08329
BDU:2015-08330
BDU:2015-08331
BDU:2015-08332
BDU:2015-08333
BDU:2015-08334
BDU:2015-08335
BDU:2015-08336
BDU:2015-08337
BDU:2015-08338
BDU:2015-08339
BDU:2015-08340
BDU:2015-08341
BDU:2015-08342
BDU:2015-08343
BDU:2015-08344
BDU:2015-08345
BDU:2015-08346
BDU:2015-08347
BDU:2015-08348
BDU:2015-08349
BDU:2015-08350
CVE-2003-0692
DSA-388

Affected Products

Kde
Kdm
Red Hat
Xfree86