Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 2.2: DSA-030-1 Critical: XFree86-1 Buffer Overflow and DoS

debian
Calendar Grey February 14, 2001
Debian Logo
Promptly upgrade your Debian XFree86 software to mitigate critical security flaws and protect against imminent risks.
Chris Evans, Joseph S

Summary

Package : xfree86-1
Vulnerability : buffer overflow, insecure tempfile handling,
denial-of-service attack
Debian-specific: no

Chris Evans, Joseph S. Myers, Michal Zalewski, Alan Cox, and others have
noted a number of problems in several components of the X Window System
sample implementation (from which XFree86 is derived). While there are no
known reports of real-world malicious exploits of any of these problems, it
is nevertheless suggested that you upgrade your XFree86 packages
immediately.

The scope of this advisory is XFree86 3.3.6 only, since that is the version
released with Debian GNU/Linux 2.2 ("potato"); Debian packages of XFree86
4.0 and later have not been released as part of a Debian distribution.

Several people are responsible for authoring the fixes to these problems,
including Aaron Campbell, Paulo Cesar Pereira de Andrade, Keith Packard,
David Dawes, Matthieu Herrb, Trevor Johnson, Colin Phipps, and Branden
Robinson.

- The X servers are vulnerable to a deni...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here