Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Scientific Linux: Important libXfont Update For Buffer Overflow Risk

Scientific Large Esm H500
Important: libXfont security update
Date: Mon, 15 Aug 2011 13:10:11 -0500
Reply-To: Troy Dawson 
Sender: Security Errata for Scientific Linux
 
From: Troy Dawson 
Subject: Security ERRATA Important: libXfont on SL5.x, SL6.x i386/x86_64
Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it."
 
MIME-Version: 1.0

Synopsis: Important: libXfont security update
Issue Date: 2011-08-11
CVE Numbers: CVE-2011-2895
 CVE-2011-2895

The libXfont packages provide the X.Org libXfont runtime library. X.Org
is an open source implementation of the X Window System.

A buffer overflow flaw was found in the way the libXfont library, used
by the X.Org server, handled malformed font files compressed using UNIX
compress. A malicious, local user could exploit this issue to
potentially execute arbitrary code with the privileges of the X.Org
server. (CVE-2011-2895)

Users of libXfont should upgrade to these updated packages, which
contain a backported patch to resolve this issue. All running X.Org
server instances must be restarted for the update to take effect.

SL5:
 i386
 libXfont-1.2.2-1.0.4.el5_7.i386.rpm
 libXfont-devel-1.2.2-1.0.4.el5_7.i386.rpm
 x86_64
 libXfont-1.2.2-1.0.4.el5_7.i386.rpm
 libXfont-1.2.2-1.0.4.el5_7.x86_64.rpm
 libXfont-devel-1.2.2-1.0.4.el5_7.i386.rpm
 libXfont-devel-1.2.2-1.0.4.el5_7.x86_64.rpm
SL6:
 i386
 libXfont-1.4.1-2.el6_1.i686.rpm
 libXfont-devel-1.4.1-2.el6_1.i686.rpm
 x86_64
 libXfont-1.4.1-2.el6_1.i686.rpm
 libXfont-1.4.1-2.el6_1.x86_64.rpm
 libXfont-devel-1.4.1-2.el6_1.i686.rpm
 libXfont-devel-1.4.1-2.el6_1.x86_64.rpm

- Scientific Linux Development Team
Your message here