GLSA: xfree

From: Daniel Ahlberg (aliz@gentoo.org)
Date: 10/24/02


From: Daniel Ahlberg <aliz@gentoo.org>
Date: Thu, 24 Oct 2002 11:58:13 +0200
To: bugtraq@securityfocus.com


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200210-006
- - --------------------------------------------------------------------

PACKAGE : xfree
SUMMARY : Shared memory may be compromised by local XFree86 users
DATE    : 2002-10-24 10:00 UTC
EXPLOIT : local

- - --------------------------------------------------------------------

Roberto Zunino discovered a vulnerability in the MIT-SHM extension of
XFree86 prior to versions 4.2.1. The vulnerability allows a local
user who can run XFree86 to gain read/write access to any shared
memory segment in the system. Although the use of shared memory
segments to store trusted data is not a common practice, by
exploiting this vulnerability the attacker potentially can get and/or
change sensitive information.

SOLUTION

It is recommended that all Gentoo Linux users who are running
x11-base/xfree-4.2.0-r12 and earlier update their systems
as follows:

emerge rsync
emerge xfree
emerge clean

- - --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
- - --------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.0 (GNU/Linux)

iD8DBQE9t8Q0fT7nyhUpoZMRAhNtAJ9LVe8VAj8cSWvNfreoZcBgdMewvACgwy64
cSJNZmLWeKfcol6ah9xIYQ8=
=fEUk
-----END PGP SIGNATURE-----



Relevant Pages

  • [Full-Disclosure] GLSA: xfree
    ... PACKAGE: xfree ... Shared memory may be compromised by local XFree86 users ... XFree86 prior to versions 4.2.1. ... It is recommended that all Gentoo Linux users who are running ...
    (Full-Disclosure)
  • X hangs
    ... The distro I'm currently using is Fedora Core 1 with XFree 4.4.0, ... altough the problem also ocurred on the same machine with slackware 9 ... and XFree86 4.3. ...
    (comp.os.linux.x)
  • Re: Numlock
    ... On Sun, 2003-07-20 at 16:23, hank wrote: ... XFree (actually XFree86) is the X-Windows that most Linux distributions ...
    (RedHat)
  • S3 Savage Graphics
    ... S3 Savage Graphics with shared memory ... from xfree and google is not really clear if linux does run or doesn't ...
    (alt.os.linux)
  • Re: S3 Savage Graphics
    ... > I am going to buy a laptop which has got the below video card: ... > S3 Savage Graphics with shared memory ... XFree is working without any problems what so ever with the native driver. ...
    (alt.os.linux)