PT-2003-1123 · Xfree86+1 · Xfree86-Truetype-Fonts+27

Published

2003-03-03

·

Updated

2008-09-05

·

CVE-2002-1472

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFree86-xf86cfg version 4.2.1 XFree86-font-utils versions 4.2.1 through 4.2.1-21 XFree86-tools versions 4.2.1 through 4.2.1-21 XFree86-75dpi-fonts versions 4.2.1 through 4.2.1-21 XFree86-cyrillic-fonts versions 4.2.1 through 4.2.1-21 XFree86-doc versions 4.2.1 through 4.2.1-21 XFree86-ISO8859-15-100dpi-fonts versions 4.2.1 through 4.2.1-21 XFree86-ISO8859-2-100dpi-fonts versions 4.2.1 through 4.2.1-21 XFree86-100dpi-fonts versions 4.2.1 through 4.2.1-21 XFree86-libs versions 4.2.1 through 4.2.1-21 XFree86-xdm versions 4.2.1 through 4.2.1-21 XFree86-2-75dpi-fonts version 4.2.1 XFree86-twm versions 4.2.1 through 4.2.1-21 XFree86-xfs versions 4.2.1 through 4.2.1-21 XFree86-4.2.1 XFree86-Xnest versions 4.2.1 through 4.2.1-21 XFree86-Mesa-libGL versions 4.2.1 through 4.2.1-21 XFree86-ISO8859-9-75dpi-fonts versions 4.2.1 through 4.2.1-21 XFree86-ISO8859-9-100dpi-fonts versions 4.2.1 through 4.2.1-21 XFree86-devel versions 4.2.1 through 4.2.1-21 XFree86-Xvfb versions 4.2.1 through 4.2.1-21 XFree86-xauth version 4.2.1-21 XFree86-truetype-fonts versions 4.2.1 through 4.2.1-21 XFree86-ISO8859-15-75dpi-fonts versions 4.2.1 through 4.2.1-21 XFree86-base-fonts versions 4.2.1 through 4.2.1-21 XFree86-Mesa-libGLU version 4.2.1-21 XFree86-ISO8859-2-75dpi-fonts version 4.2.1-21
Description The issue involves multiple vulnerabilities in the XFree86 package of the Red Hat Linux operating system. These vulnerabilities can be exploited remotely and may lead to a breach of confidentiality, integrity, and availability of protected information. Additionally, an untrusted search path vulnerability in libX11.so, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD PRELOAD environment variable that points to a malicious module.
Recommendations For XFree86-xf86cfg version 4.2.1, update to a version that is not affected by the vulnerability. For XFree86-font-utils versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-tools versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-75dpi-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-cyrillic-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-doc versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-ISO8859-15-100dpi-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-ISO8859-2-100dpi-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-100dpi-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-libs versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-xdm versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-2-75dpi-fonts version 4.2.1, update to a version that is not affected by the vulnerability. For XFree86-twm versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-xfs versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-4.2.1, update to a version that is not affected by the vulnerability. For XFree86-Xnest versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-Mesa-libGL versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-ISO8859-9-75dpi-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-ISO8859-9-100dpi-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-devel versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-Xvfb versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-xauth version 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-truetype-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-ISO8859-15-75dpi-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-base-fonts versions 4.2.1 through 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-Mesa-libGLU version 4.2.1-21, update to a version that is not affected by the vulnerability. For XFree86-ISO8859-2-75dpi-fonts version 4.2.1-21, update to a version that is not affected by the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-08269
BDU:2015-08270
BDU:2015-08271
BDU:2015-08272
BDU:2015-08273
BDU:2015-08274
BDU:2015-08275
BDU:2015-08276
BDU:2015-08277
BDU:2015-08278
BDU:2015-08279
BDU:2015-08280
BDU:2015-08281
BDU:2015-08282
BDU:2015-08283
BDU:2015-08284
BDU:2015-08285
BDU:2015-08286
BDU:2015-08287
BDU:2015-08288
BDU:2015-08289
BDU:2015-08290
BDU:2015-08291
BDU:2015-08292
BDU:2015-08293
BDU:2015-08294
BDU:2015-08295
BDU:2015-08296
BDU:2015-08297
BDU:2015-08298
BDU:2015-08299
BDU:2015-08300
BDU:2015-08301
BDU:2015-08302
BDU:2015-08303
BDU:2015-08304
BDU:2015-08305
BDU:2015-08306
BDU:2015-08307
BDU:2015-08308
BDU:2015-08309
BDU:2015-08310
BDU:2015-08311
BDU:2015-08312
BDU:2015-08313
BDU:2015-08314
BDU:2015-08315
BDU:2015-08316
CVE-2002-1472

Affected Products

Red Hat
Xfree86-100Dpi-Fonts
Xfree86-2-75Dpi-Fonts
Xfree86-4.2.1
Xfree86-75Dpi-Fonts
Xfree86-Iso8859-15-100Dpi-Fonts
Xfree86-Iso8859-15-75Dpi-Fonts
Xfree86-Iso8859-2-100Dpi-Fonts
Xfree86-Iso8859-2-75Dpi-Fonts
Xfree86-Iso8859-9-100Dpi-Fonts
Xfree86-Iso8859-9-75Dpi-Fonts
Xfree86-Mesa-Libgl
Xfree86-Xnest
Xfree86-Xvfb
Xfree86-Base-Fonts
Xfree86-Cyrillic-Fonts
Xfree86-Devel
Xfree86-Doc
Xfree86-Font-Utils
Xfree86-Libs
Xfree86-Tools
Xfree86-Truetype-Fonts
Xfree86-Twm
Xfree86-Xauth
Xfree86-Xdm
Xfree86-Xf86Cfg
Xfree86-Xfs
Libx11