Scientific Linux alert SL-libX-20110811 (libXfont)
From: | Troy Dawson <dawson@fnal.gov> | |
To: | "scientific-linux-errata@fnal.gov" <scientific-linux-errata@fnal.gov> | |
Subject: | Security ERRATA Important: libXfont on SL5.x, SL6.x i386/x86_64 | |
Date: | Mon, 15 Aug 2011 13:10:11 -0500 | |
Message-ID: | <4E496103.3030504@fnal.gov> |
Synopsis: Important: libXfont security update Issue Date: 2011-08-11 CVE Numbers: CVE-2011-2895 CVE-2011-2895 The libXfont packages provide the X.Org libXfont runtime library. X.Org is an open source implementation of the X Window System. A buffer overflow flaw was found in the way the libXfont library, used by the X.Org server, handled malformed font files compressed using UNIX compress. A malicious, local user could exploit this issue to potentially execute arbitrary code with the privileges of the X.Org server. (CVE-2011-2895) Users of libXfont should upgrade to these updated packages, which contain a backported patch to resolve this issue. All running X.Org server instances must be restarted for the update to take effect. SL5: i386 libXfont-1.2.2-1.0.4.el5_7.i386.rpm libXfont-devel-1.2.2-1.0.4.el5_7.i386.rpm x86_64 libXfont-1.2.2-1.0.4.el5_7.i386.rpm libXfont-1.2.2-1.0.4.el5_7.x86_64.rpm libXfont-devel-1.2.2-1.0.4.el5_7.i386.rpm libXfont-devel-1.2.2-1.0.4.el5_7.x86_64.rpm SL6: i386 libXfont-1.4.1-2.el6_1.i686.rpm libXfont-devel-1.4.1-2.el6_1.i686.rpm x86_64 libXfont-1.4.1-2.el6_1.i686.rpm libXfont-1.4.1-2.el6_1.x86_64.rpm libXfont-devel-1.4.1-2.el6_1.i686.rpm libXfont-devel-1.4.1-2.el6_1.x86_64.rpm - Scientific Linux Development Team