Security Advisory XFree86 security update

Advisory: RHSA-2003:065-13
Type: Security Advisory
Severity: Important
Issued on: 2003-06-25
Last updated on: 2003-06-25
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2001-1409
CVE-2002-0164
CVE-2002-1510
CVE-2003-0063
CVE-2003-0071

Details

Updated XFree86 packages that resolve various security issues and
additionally provide a number of bug fixes and enhancements are now
available for Red Hat Enterprise Linux 2.1.

XFree86 is an implementation of the X Window System, which provides the
graphical user interface, video drivers, etc. for Linux systems.

A number of security vulnerabilities have been found and fixed. In
addition, various other bug fixes, driver updates, and other enhancements
have been made.

Security fixes:

Xterm, provided as part of the XFree86 packages, provides an escape
sequence for reporting the current window title. This escape sequence
essentially takes the current title and places it directly on the command
line. An attacker can craft an escape sequence that sets the victim's Xterm
window title to an arbitrary command, and then reports it to the command
line. Since it is not possible to embed a carriage return into the window
title, the attacker would then have to convince the victim to press Enter
for the shell to process the title as a command, although the attacker
could craft other escape sequences that might convince the victim to do so.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2003-0063 to this issue.

It is possible to lock up versions of Xterm by sending an invalid DEC
UDK escape sequence. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0071 to this issue.

The xdm display manager, with the authComplain variable set to false,
allows arbitrary attackers to connect to the X server if the xdm auth
directory does not exist. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2002-1510 to this issue.

These erratum packages also contain an updated fix for CAN-2002-0164, a
vulnerability in the MIT-SHM extension of the X server that allows local
users to read and write arbitrary shared memory. The original fix did not
cover the case where the X server is started from xdm.

The X server was setting the /dev/dri directory permissions incorrectly,
which resulted in the directory being world writable. It now sets the
directory permissions to a safe value. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2001-1409 to
this issue.

Driver updates and other fixes:

The Rage 128 video driver (r128) has been updated to provide 2D support
for all previously unsupported ATI Rage 128 hardware. DRI 3D support
should also work on the majority of Rage 128 hardware.

Bad page size assumptions in the ATI Radeon video driver (radeon) have
been fixed, allowing the driver to work properly on ia64 and other
architectures where the page size is not fixed.

A long-standing XFree86 bug has been fixed. This bug occurs when any form
of system clock skew (such as NTP clock synchronization, APM suspend/resume
cycling on laptops, daylight savings time changeover, or even manually
setting the system clock forward or backward) could result in odd
application behavior, mouse and keyboard lockups, or even an X server hang
or crash.

The S3 Savage driver (savage) has been updated to the upstream author's
latest version "1.1.27t", which should fix numerous bugs reported by
various users, as well as adding support for some newer savage hardware.

Users are advised to upgrade to these updated packages, which contain
XFree86 version 4.1.0 with patches correcting these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

Please note that this update is available via Red Hat Network. To use Red
Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
XFree86-4.1.0-49.RHEL.src.rpm     8d4ff58c390f0c48e9b4afee3668e298
 
IA-32:
XFree86-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    61bf8a8d9d9607262fda89fa27b93b81
XFree86-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    8c49b523a8c818ba32b74ac0f5f317a9
XFree86-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    1e4cdc615caeea0273aee974ca5afb5f
XFree86-ISO8859-15-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    6f2f98d667440a905f89e0a70cfb2ae8
XFree86-ISO8859-15-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    235be98cd5b1306f7e03ce1506706a04
XFree86-ISO8859-2-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    080d463c9c4a16e97295acebd85b0421
XFree86-ISO8859-2-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    c4432e989aa032e2e903837970917bc2
XFree86-ISO8859-9-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    93f98b89e4d2b3e3fbfd4c345d5c16b0
XFree86-ISO8859-9-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    88ccb20dc2ff05915099bc3f2ced53b6
XFree86-Xnest-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    1fcb79c5903f0d72a3e3733d2f7ec9cd
XFree86-Xvfb-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    6210cb57930471f59cc8185d84cbd2ec
XFree86-cyrillic-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    37416aedeae15bb9979d90e3c74662f2
XFree86-devel-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    2ba38e4ec296b7dc2c514bd1c2064001
XFree86-doc-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    456a84f25c9c746fd1e73fb07c46449e
XFree86-libs-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    7caed8573e18237be0e8f7de32785e32
XFree86-tools-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    0c9ee5166335972e8e565856add8094c
XFree86-twm-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    9041ea9512f0df3ca5860c8b4dfa5510
XFree86-xdm-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    285c12ee87f9fc3b98bbae399741ceab
XFree86-xf86cfg-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    5dfb51af05ea2dfbacbd91b8cd0a8a61
XFree86-xfs-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    0e44d81b2d39658b3520f1e477044430
 
IA-64:
XFree86-100dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    061a4b7704f7cfe78852254214482e05
XFree86-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    d7bc3098127522eeb2567f32b1cfc4f6
XFree86-75dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    a3b6c692f4528afef401af6eabe0aeb5
XFree86-ISO8859-15-100dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    fe063a1956e2932e95c58ff44185e10a
XFree86-ISO8859-15-75dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    15f30ea234fdc145edbf823003c63fd8
XFree86-ISO8859-2-100dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    0f1fd179b78173493d48a7e6c6ffbd28
XFree86-ISO8859-2-75dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    cd0f95b3c4ffc56a4bc633ac41b6674d
XFree86-ISO8859-9-100dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    dccb2cb87d69d70213a336fc57e5d75d
XFree86-ISO8859-9-75dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    1ddff085543fe4caa8643e22b425fb2e
XFree86-Xnest-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    811b4ded3fcc4affab3d147f351bf2e9
XFree86-Xvfb-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    9f6aea1a2585676e55d9feccc123c1f3
XFree86-cyrillic-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    2ed2200894c8a6ffb19f549503a3f09e
XFree86-devel-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    e290caa964e3f131790dfd16450ae99b
XFree86-doc-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    aad5ec33968264c0ee53ce7dfe5b9e88
XFree86-libs-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    dd6734a7d88f1a858627fcee2b0c28cb
XFree86-tools-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    88467890049cd881f03b4825de06c9d6
XFree86-twm-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    471abb90c03d734218545e69aeee4cda
XFree86-xdm-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    f11c4377d6f716efbbf018237f100bfb
XFree86-xfs-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    f106837b43004a2f0b1dc1574f388e81
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
XFree86-4.1.0-49.RHEL.src.rpm     8d4ff58c390f0c48e9b4afee3668e298
 
IA-32:
XFree86-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    61bf8a8d9d9607262fda89fa27b93b81
XFree86-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    8c49b523a8c818ba32b74ac0f5f317a9
XFree86-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    1e4cdc615caeea0273aee974ca5afb5f
XFree86-ISO8859-15-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    6f2f98d667440a905f89e0a70cfb2ae8
XFree86-ISO8859-15-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    235be98cd5b1306f7e03ce1506706a04
XFree86-ISO8859-2-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    080d463c9c4a16e97295acebd85b0421
XFree86-ISO8859-2-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    c4432e989aa032e2e903837970917bc2
XFree86-ISO8859-9-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    93f98b89e4d2b3e3fbfd4c345d5c16b0
XFree86-ISO8859-9-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    88ccb20dc2ff05915099bc3f2ced53b6
XFree86-Xnest-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    1fcb79c5903f0d72a3e3733d2f7ec9cd
XFree86-Xvfb-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    6210cb57930471f59cc8185d84cbd2ec
XFree86-cyrillic-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    37416aedeae15bb9979d90e3c74662f2
XFree86-devel-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    2ba38e4ec296b7dc2c514bd1c2064001
XFree86-doc-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    456a84f25c9c746fd1e73fb07c46449e
XFree86-libs-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    7caed8573e18237be0e8f7de32785e32
XFree86-tools-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    0c9ee5166335972e8e565856add8094c
XFree86-twm-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    9041ea9512f0df3ca5860c8b4dfa5510
XFree86-xdm-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    285c12ee87f9fc3b98bbae399741ceab
XFree86-xf86cfg-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    5dfb51af05ea2dfbacbd91b8cd0a8a61
XFree86-xfs-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    0e44d81b2d39658b3520f1e477044430
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
XFree86-4.1.0-49.RHEL.src.rpm     8d4ff58c390f0c48e9b4afee3668e298
 
IA-32:
XFree86-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    61bf8a8d9d9607262fda89fa27b93b81
XFree86-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    8c49b523a8c818ba32b74ac0f5f317a9
XFree86-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    1e4cdc615caeea0273aee974ca5afb5f
XFree86-ISO8859-15-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    6f2f98d667440a905f89e0a70cfb2ae8
XFree86-ISO8859-15-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    235be98cd5b1306f7e03ce1506706a04
XFree86-ISO8859-2-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    080d463c9c4a16e97295acebd85b0421
XFree86-ISO8859-2-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    c4432e989aa032e2e903837970917bc2
XFree86-ISO8859-9-100dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    93f98b89e4d2b3e3fbfd4c345d5c16b0
XFree86-ISO8859-9-75dpi-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    88ccb20dc2ff05915099bc3f2ced53b6
XFree86-Xnest-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    1fcb79c5903f0d72a3e3733d2f7ec9cd
XFree86-Xvfb-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    6210cb57930471f59cc8185d84cbd2ec
XFree86-cyrillic-fonts-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    37416aedeae15bb9979d90e3c74662f2
XFree86-devel-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    2ba38e4ec296b7dc2c514bd1c2064001
XFree86-doc-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    456a84f25c9c746fd1e73fb07c46449e
XFree86-libs-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    7caed8573e18237be0e8f7de32785e32
XFree86-tools-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    0c9ee5166335972e8e565856add8094c
XFree86-twm-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    9041ea9512f0df3ca5860c8b4dfa5510
XFree86-xdm-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    285c12ee87f9fc3b98bbae399741ceab
XFree86-xf86cfg-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    5dfb51af05ea2dfbacbd91b8cd0a8a61
XFree86-xfs-4.1.0-49.RHEL.i386.rpm
File outdated by:  RHSA-2008:0512
    0e44d81b2d39658b3520f1e477044430
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
XFree86-4.1.0-49.RHEL.src.rpm     8d4ff58c390f0c48e9b4afee3668e298
 
IA-64:
XFree86-100dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    061a4b7704f7cfe78852254214482e05
XFree86-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    d7bc3098127522eeb2567f32b1cfc4f6
XFree86-75dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    a3b6c692f4528afef401af6eabe0aeb5
XFree86-ISO8859-15-100dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    fe063a1956e2932e95c58ff44185e10a
XFree86-ISO8859-15-75dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    15f30ea234fdc145edbf823003c63fd8
XFree86-ISO8859-2-100dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    0f1fd179b78173493d48a7e6c6ffbd28
XFree86-ISO8859-2-75dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    cd0f95b3c4ffc56a4bc633ac41b6674d
XFree86-ISO8859-9-100dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    dccb2cb87d69d70213a336fc57e5d75d
XFree86-ISO8859-9-75dpi-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    1ddff085543fe4caa8643e22b425fb2e
XFree86-Xnest-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    811b4ded3fcc4affab3d147f351bf2e9
XFree86-Xvfb-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    9f6aea1a2585676e55d9feccc123c1f3
XFree86-cyrillic-fonts-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    2ed2200894c8a6ffb19f549503a3f09e
XFree86-devel-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    e290caa964e3f131790dfd16450ae99b
XFree86-doc-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    aad5ec33968264c0ee53ce7dfe5b9e88
XFree86-libs-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    dd6734a7d88f1a858627fcee2b0c28cb
XFree86-tools-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    88467890049cd881f03b4825de06c9d6
XFree86-twm-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    471abb90c03d734218545e69aeee4cda
XFree86-xdm-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    f11c4377d6f716efbbf018237f100bfb
XFree86-xfs-4.1.0-49.RHEL.ia64.rpm
File outdated by:  RHSA-2008:0512
    f106837b43004a2f0b1dc1574f388e81
 
(The unlinked packages above are only available from the Red Hat Network)

References


Keywords

r128, radeon, savage, security, XFree86, xterm


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/