GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Oct 22, 2011 7:26 pm Post subject: [ GLSA 201110-19 ] X.Org X Server: Multiple vulnerabilities |
|
|
Gentoo Linux Security Advisory
Title: X.Org X Server: Multiple vulnerabilities (GLSA 201110-19)
Severity: normal
Exploitable: local
Date: October 22, 2011
Bug(s): #387069
ID: 201110-19
Synopsis
Multiple vulnerabilities in the X.Org X server might allow local
attackers to disclose information.
Background
The X Window System is a graphical windowing system based on a
client/server model.
Affected Packages
Package: x11-base/xorg-server
Vulnerable: < 1.10.4-r1
Unaffected: >= 1.9.5-r1 < 1.9.6
Unaffected: >= 1.10.4-r1
Architectures: All supported architectures
Description
vladz reported the following vulnerabilities in the X.Org X server: - The X.Org X server follows symbolic links when trying to access the
lock file for a X display, showing a predictable behavior depending on
the file type of the link target (CVE-2011-4028).
- The X.Org X server lock file mechanism allows for a race condition to
cause the X server to modify the file permissions of an arbitrary file
to 0444 (CVE-2011-4029).
Impact
A local attacker could exploit these vulnerabilities to disclose
information by making arbitrary files on a system world-readable or gain
information whether a specified file exists on the system and whether it
is a file, directory, or a named pipe.
Workaround
There is no known workaround at this time.
Resolution
All X.Org X Server 1.9 users should upgrade to the latest 1.9 version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=x11-base/xorg-server-1.9.5-r1"
| All X.Org X Server 1.10 users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=x11-base/xorg-server-1.10.4-r1"
|
References
CVE-2011-4028
CVE-2011-4029 |
|