Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Slackware: 2006-123-01 Critical: Xorg Server Overflow Code Execution

slackware
Calendar Grey May 3, 2006
Dist Slackware Esm H88
The latest update for the Xorg server in Slackware addresses a buffer overflow vulnerability that could enable the execution of arbitrary code.
New xorg and xorg-devel packages are available for Slackware 10.1, 10.2, and -current to fix a security issue

Summary

Here are the details from the Slackware 10.2 ChangeLog: patches/packages/x11-6.8.2-i486-5.tgz: Patched with x11r6.9.0-mitri.diff and recompiled. A typo in the X render extension allows an X client to crash the server and possibly to execute arbitrary code as the X server user (typically this is "root".) The CVE entry for this issue may be found here: https://www.cve.org/CVERecord?id=CVE-2006-1526 The advisory from X.Org may be found here: https://lists.freedesktop.org/archives/xorg/2006-May/015136.html (* Security fix *) patches/packages/x11-devel-6.8.2-i486-5.tgz: Patched and recompiled libXrender. (* Security fix *)

Where Find New Packages

Updated packages for Slackware 10.1:
Updated packages for Slackware 10.2:
Updated packages for Slackware -current:

MD5 Signatures

Slackware 10.1 packages: 0adae00722f78242961ebdd8e874a97e x11-6.8.1-i486-5.tgz 7e1072009150f2d02bb958fdbf8920ed x11-devel-6.8.1-i486-5.tgz
Slackware 10.2 packages: 95a228488f09978c4a3468fb027a49c8 x11-6.8.2-i486-5.tgz 86f2fe06649b2d120f8f0fb1ad76f341 x11-devel-6.8.2-i486-5.tgz
Slackware -current packages: 2aa5db26d003137c01d2688e644d0b9d x11-6.9.0-i486-4.tgz 39b4feb60a97e79100962ebec50d9208 x11-devel-6.9.0-i486-4.tgz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the packages as root: # upgradepkg x11-6.8.2-i486-5.tgz x11-devel-6.8.2-i486-5.tgz

Related News

Your message here