Secunia Logo
Netsikker nu! 2008
 
SuSE update for XFree86
Secunia Advisory: SA10957
Release Date: 2004-02-24
Popularity: 7,200 views

Critical:
Not critical
Impact: DoS
Where: Local system
Solution Status: Vendor Patch

OS:SuSE eMail Server 3.x
SuSE Linux 8.x
SuSE Linux 9.0
SuSE Linux Connectivity Server
SuSE Linux Enterprise Server 7
SuSE Linux Enterprise Server 8
SuSE Linux Firewall on CD/Admin host
SuSE Linux Office Server

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2004-0083
CVE-2004-0084
CVE-2004-0106


Description:
SuSE has issued patches, which fix some vulnerabilities in XFree86. These can be exploited by malicious, local users to crash the X server on a vulnerable system.

Escalation of privileges is reportedly not possible, since this is prevented by ProPolice.

For more information:
SA10824

Solution:
Updated packages:

SuSE-9.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/XFree86-4.3.0.1-46.i586.rpm
dcaadc2b9438995c9a3ac6e4fc7bf181
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...586/XFree86-4.3.0.1-46.i586.patch.rpm
f094861c9a0fbb5f27d168b680fe1a5b
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/src/XFree86-4.3.0.1-46.src.rpm
824c6173693342a033f75c503592e7e0

SuSE-8.2:
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/XFree86-4.3.0-120.i586.rpm
f1f01280e6e8a5a2f091a04c5836a51d
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...i586/XFree86-4.3.0-120.i586.patch.rpm
16ba90ef0ad607d1547cda7734b28750
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/src/XFree86-4.3.0-120.src.rpm
4100735436d4c8801c6add673fceb29e

SuSE-8.1:
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/xf86-4.2.0-257.i586.rpm
9ed1fc5ec83a42a85315391387610e6b
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...pm/i586/xf86-4.2.0-257.i586.patch.rpm
9652732385f8670ea9d36151378b7428
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/src/xf86-4.2.0-257.src.rpm
e1d73191d2aabe3a6dda677e6fd716bc

SuSE-8.0:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/x1/xf86-4.2.0-257.i386.rpm
9b69aac017a0ac9905e3fc4e9594d435
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.0/x1/xf86-4.2.0-257.i386.patch.rpm
3076136bcdf20132f343768e4a71c7a2
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/xf86-4.2.0-257.src.rpm
1775eef155f4afdc9a3a08ff31a38607

Opteron x86_64 Platform:

SuSE-9.0:
ftp://ftp.suse.com/pub/suse/x86_64/up.../x86_64/XFree86-4.3.0.1-52.x86_64.rpm
1714cb2eb566fab0e29277db9f9d2572
patch rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/up...4/XFree86-4.3.0.1-52.x86_64.patch.rpm
930944efc868b28d87a69a9543206546
source rpm(s):
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/src/XFree86-4.3.0.1-52.src.rpm
ee67773fcad341912b617d397991ed32

Original Advisory:
http://www.suse.de/de/security/2004_06_xf86.html

Other References:
SA10824:
http://secunia.com/advisories/10824/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB "url" bbcode Script Insertion Vulnerability // 37 views
2. My PHP Indexer "d" File Disclosure Vulnerability // 32 views
3. phpBB BBcode "url" Script Insertion Vulnerability // 30 views
4. WinFTP "PASV" Denial of Service Vulnerability // 30 views
5. Joomla Ignite Gallery Component "gallery" SQL Injection // 27 views
6. Joomla Mad4Joomla Mailforms Component "jid" SQL Injection // 26 views
7. MunzurSoft Wep Portal W3 "kat" SQL Injection Vulnerability // 21 views
8. Real Estates Classifieds "cat" SQL Injection Vulnerability // 21 views
9. chm2pdf Insecure Temporary Directories // 21 views
10. ScriptsEz Mini Hosting Panel "dir" File Disclosure // 20 views