Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA 443-1 Critical: XFree86 Buffer Overflow Security Issue

debian
Calendar Grey February 20, 2004
Debian Logo
A variety of risks connected to memory overflow issues and insufficient input verification have been addressed in the most recent security patch for XFree86 on Debian.
Various buffer-overflow and input-non-validation vulnerabilities are fixed in this patch.

Summary

A number of vulnerabilities have been discovered in XFree86:

CAN-2004-0083: Buffer overflow in ReadFontAlias from dirfile.c of
XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to
execute arbitrary code via a font alias file (font.alias) with a long
token, a different vulnerability than CAN-2004-0084.

CAN-2004-0084: Buffer overflow in the ReadFontAlias function in XFree86
4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows
local or remote authenticated users to execute arbitrary code via a
malformed entry in the font alias (font.alias) file, a different
vulnerability than CAN-2004-0083.

CAN-2004-0106: Miscellaneous additional flaws in XFree86's handling of
font files.

CAN-2003-0690: xdm does not verify whether the pam_setcred function call
succeeds, which may allow attackers to gain root privileges by
triggering error conditions within PAM modules, as demonstrated in
certain configurations of the MIT pam_krb5 module.

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xfree86

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here