Date:         Wed, 19 Sep 2007 16:45:08 -0500
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for xorg-x11 on SL4.x i386/x86_64
Comments: To: scientific-linux-errata@fnal.gov

Synopsis:	Moderate: xorg-x11 security update
Issue date:	2007-09-19
CVE Names:	CVE-2007-4730

A flaw was found in the way X.Org's composite extension handles 32 bit
color depth windows while running in 16 bit color depth mode. If an X.org
server has enabled the composite extension, it may be possible for a
malicious authorized client to cause a denial of service (crash) or
potentially execute arbitrary code with the privileges of the X.org server.
(CVE-2007-4730)

Please note this flaw can only be triggered when using a compositing window
manager. Scientific Linux 4 does not ship with a compositing window
manager.

SL 4.x

   SRPMS:
xorg-x11-6.8.2-1.EL.31.src.rpm
   i386:
xorg-x11-6.8.2-1.EL.31.i386.rpm
xorg-x11-deprecated-libs-6.8.2-1.EL.31.i386.rpm
xorg-x11-deprecated-libs-devel-6.8.2-1.EL.31.i386.rpm
xorg-x11-devel-6.8.2-1.EL.31.i386.rpm
xorg-x11-doc-6.8.2-1.EL.31.i386.rpm
xorg-x11-font-utils-6.8.2-1.EL.31.i386.rpm
xorg-x11-libs-6.8.2-1.EL.31.i386.rpm
xorg-x11-Mesa-libGL-6.8.2-1.EL.31.i386.rpm
xorg-x11-Mesa-libGLU-6.8.2-1.EL.31.i386.rpm
xorg-x11-sdk-6.8.2-1.EL.31.i386.rpm
xorg-x11-tools-6.8.2-1.EL.31.i386.rpm
xorg-x11-twm-6.8.2-1.EL.31.i386.rpm
xorg-x11-xauth-6.8.2-1.EL.31.i386.rpm
xorg-x11-xdm-6.8.2-1.EL.31.i386.rpm
xorg-x11-Xdmx-6.8.2-1.EL.31.i386.rpm
xorg-x11-xfs-6.8.2-1.EL.31.i386.rpm
xorg-x11-Xnest-6.8.2-1.EL.31.i386.rpm
xorg-x11-Xvfb-6.8.2-1.EL.31.i386.rpm
   x86_64:
xorg-x11-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-deprecated-libs-6.8.2-1.EL.31.i386.rpm
xorg-x11-deprecated-libs-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-deprecated-libs-devel-6.8.2-1.EL.31.i386.rpm
xorg-x11-deprecated-libs-devel-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-devel-6.8.2-1.EL.31.i386.rpm
xorg-x11-devel-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-doc-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-font-utils-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-libs-6.8.2-1.EL.31.i386.rpm
xorg-x11-libs-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-Mesa-libGL-6.8.2-1.EL.31.i386.rpm
xorg-x11-Mesa-libGL-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-Mesa-libGLU-6.8.2-1.EL.31.i386.rpm
xorg-x11-Mesa-libGLU-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-sdk-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-tools-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-twm-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-xauth-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-xdm-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-Xdmx-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-xfs-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-Xnest-6.8.2-1.EL.31.x86_64.rpm
xorg-x11-Xvfb-6.8.2-1.EL.31.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2007-4730 xorg-x11 SL4.x i386/x86_64

Moderate: xorg-x11 security update

Summary

Date:         Wed, 19 Sep 2007 16:45:08 -0500Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for xorg-x11 on SL4.x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis:	Moderate: xorg-x11 security updateIssue date:	2007-09-19CVE Names:	CVE-2007-4730A flaw was found in the way X.Org's composite extension handles 32 bitcolor depth windows while running in 16 bit color depth mode. If an X.orgserver has enabled the composite extension, it may be possible for amalicious authorized client to cause a denial of service (crash) orpotentially execute arbitrary code with the privileges of the X.org server.(CVE-2007-4730)Please note this flaw can only be triggered when using a compositing windowmanager. Scientific Linux 4 does not ship with a compositing windowmanager.SL 4.x   SRPMS:xorg-x11-6.8.2-1.EL.31.src.rpm   i386:xorg-x11-6.8.2-1.EL.31.i386.rpmxorg-x11-deprecated-libs-6.8.2-1.EL.31.i386.rpmxorg-x11-deprecated-libs-devel-6.8.2-1.EL.31.i386.rpmxorg-x11-devel-6.8.2-1.EL.31.i386.rpmxorg-x11-doc-6.8.2-1.EL.31.i386.rpmxorg-x11-font-utils-6.8.2-1.EL.31.i386.rpmxorg-x11-libs-6.8.2-1.EL.31.i386.rpmxorg-x11-Mesa-libGL-6.8.2-1.EL.31.i386.rpmxorg-x11-Mesa-libGLU-6.8.2-1.EL.31.i386.rpmxorg-x11-sdk-6.8.2-1.EL.31.i386.rpmxorg-x11-tools-6.8.2-1.EL.31.i386.rpmxorg-x11-twm-6.8.2-1.EL.31.i386.rpmxorg-x11-xauth-6.8.2-1.EL.31.i386.rpmxorg-x11-xdm-6.8.2-1.EL.31.i386.rpmxorg-x11-Xdmx-6.8.2-1.EL.31.i386.rpmxorg-x11-xfs-6.8.2-1.EL.31.i386.rpmxorg-x11-Xnest-6.8.2-1.EL.31.i386.rpmxorg-x11-Xvfb-6.8.2-1.EL.31.i386.rpm   x86_64:xorg-x11-6.8.2-1.EL.31.x86_64.rpmxorg-x11-deprecated-libs-6.8.2-1.EL.31.i386.rpmxorg-x11-deprecated-libs-6.8.2-1.EL.31.x86_64.rpmxorg-x11-deprecated-libs-devel-6.8.2-1.EL.31.i386.rpmxorg-x11-deprecated-libs-devel-6.8.2-1.EL.31.x86_64.rpmxorg-x11-devel-6.8.2-1.EL.31.i386.rpmxorg-x11-devel-6.8.2-1.EL.31.x86_64.rpmxorg-x11-doc-6.8.2-1.EL.31.x86_64.rpmxorg-x11-font-utils-6.8.2-1.EL.31.x86_64.rpmxorg-x11-libs-6.8.2-1.EL.31.i386.rpmxorg-x11-libs-6.8.2-1.EL.31.x86_64.rpmxorg-x11-Mesa-libGL-6.8.2-1.EL.31.i386.rpmxorg-x11-Mesa-libGL-6.8.2-1.EL.31.x86_64.rpmxorg-x11-Mesa-libGLU-6.8.2-1.EL.31.i386.rpmxorg-x11-Mesa-libGLU-6.8.2-1.EL.31.x86_64.rpmxorg-x11-sdk-6.8.2-1.EL.31.x86_64.rpmxorg-x11-tools-6.8.2-1.EL.31.x86_64.rpmxorg-x11-twm-6.8.2-1.EL.31.x86_64.rpmxorg-x11-xauth-6.8.2-1.EL.31.x86_64.rpmxorg-x11-xdm-6.8.2-1.EL.31.x86_64.rpmxorg-x11-Xdmx-6.8.2-1.EL.31.x86_64.rpmxorg-x11-xfs-6.8.2-1.EL.31.x86_64.rpmxorg-x11-Xnest-6.8.2-1.EL.31.x86_64.rpmxorg-x11-Xvfb-6.8.2-1.EL.31.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News