PT-2003-1118 · Xfree86+1 · Xfree86-Truetype-Fonts+23

Published

2003-06-18

·

Updated

2010-05-25

·

CVE-2001-1409

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFree86-xf86cfg versions 4.1.0 through 4.2.1 XFree86-font-utils versions 4.1.0 through 4.2.1-21 XFree86-ISO8859-9-75dpi-fonts versions 4.1.0 through 4.2.1-21 XFree86-tools versions 4.1.0 through 4.2.1-21 XFree86-devel versions 4.1.0 through 4.2.1-21 XFree86-75dpi-fonts versions 4.1.0 through 4.2.1-21 XFree86-doc versions 4.1.0 through 4.2.1-21 XFree86-cyrillic-fonts versions 4.1.0 through 4.2.1-21 XFree86-ISO8859-2-100dpi-fonts versions 4.1.0 through 4.2.1-21 XFree86-ISO8859-15-100dpi-fonts versions 4.1.0 through 4.2.1-21 XFree86-100dpi-fonts versions 4.1.0 through 4.2.1-21 XFree86-libs versions 4.1.0 through 4.2.1-21 XFree86-xdm versions 4.1.0 through 4.2.1-21 XFree86-Xnest versions 4.1.0 through 4.2.1-21 XFree86-xfs versions 4.1.0 through 4.2.1-21 XFree86-Mesa-libGL versions 4.1.0 through 4.2.1-21 XFree86-Mesa-libGLU versions 4.1.0 through 4.2.1-21 XFree86-ISO8859-2-75dpi-fonts versions 4.1.0 through 4.2.1-21 XFree86-ISO8859-15-75dpi-fonts versions 4.1.0 through 4.2.1-21 XFree86-truetype-fonts versions 4.1.0 through 4.2.1-21 XFree86-base-fonts versions 4.1.0 through 4.2.1-21 XFree86-twm versions 4.1.0 through 4.2.1-21 XFree86-xauth versions 4.1.0 through 4.2.1-21 XFree86-Xvfb versions 4.1.0 through 4.2.1-21
Description The XFree86 package in Red Hat Linux has multiple vulnerabilities that can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The issue is related to insecure permissions in the /dev/dri directory, which can allow local users to replace or create files in the root file system.
Recommendations For each affected version of XFree86, update to a version that is not vulnerable to these issues. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available. For the dexconf issue in XFree86 Xserver 4.1.0-2, ensure that the /dev/dri directory has secure permissions to prevent local users from replacing or creating files in the root file system. Restrict access to the vulnerable modules and fonts to minimize the risk of exploitation. Avoid using the vulnerable packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08248
BDU:2015-08249
BDU:2015-08250
BDU:2015-08251
BDU:2015-08252
BDU:2015-08253
BDU:2015-08254
BDU:2015-08255
BDU:2015-08256
BDU:2015-08257
BDU:2015-08258
BDU:2015-08259
BDU:2015-08260
BDU:2015-08261
BDU:2015-08262
BDU:2015-08263
BDU:2015-08264
BDU:2015-08265
BDU:2015-08266
BDU:2015-08267
BDU:2015-08268
BDU:2015-08269
BDU:2015-08270
BDU:2015-08271
BDU:2015-08272
BDU:2015-08273
BDU:2015-08274
BDU:2015-08275
BDU:2015-08276
BDU:2015-08277
BDU:2015-08278
BDU:2015-08279
BDU:2015-08280
BDU:2015-08281
BDU:2015-08282
BDU:2015-08283
BDU:2015-08284
BDU:2015-08285
BDU:2015-08286
BDU:2015-08287
BDU:2015-08288
BDU:2015-08289
BDU:2015-08290
BDU:2015-08291
BDU:2015-08292
BDU:2015-08293
BDU:2015-08294
BDU:2015-08295
BDU:2015-08296
BDU:2015-08297
BDU:2015-08298
BDU:2015-08299
BDU:2015-08300
BDU:2015-08301
BDU:2015-08302
BDU:2015-08303
BDU:2015-08304
BDU:2015-08305
BDU:2015-08306
BDU:2015-08307
BDU:2015-08308
BDU:2015-08309
BDU:2015-08310
BDU:2015-08311
BDU:2015-08312
BDU:2015-08313
BDU:2015-08314
BDU:2015-08315
BDU:2015-08316
CVE-2001-1409

Affected Products

Red Hat
Xfree86-100Dpi-Fonts
Xfree86-75Dpi-Fonts
Xfree86-Iso8859-15-100Dpi-Fonts
Xfree86-Iso8859-15-75Dpi-Fonts
Xfree86-Iso8859-2-100Dpi-Fonts
Xfree86-Iso8859-2-75Dpi-Fonts
Xfree86-Iso8859-9-75Dpi-Fonts
Xfree86-Mesa-Libgl
Xfree86-Xnest
Xfree86-Xvfb
Xfree86-Base-Fonts
Xfree86-Cyrillic-Fonts
Xfree86-Devel
Xfree86-Doc
Xfree86-Font-Utils
Xfree86-Libs
Xfree86-Tools
Xfree86-Truetype-Fonts
Xfree86-Twm
Xfree86-Xauth
Xfree86-Xdm
Xfree86-Xf86Cfg
Xfree86-Xfs