Secunia Logo  
 
SUSE update for XFree86 and Xorg
Secunia Advisory: SA23758
Release Date: 2007-01-15
Popularity: 6,132 views

Critical:
Less critical
Impact: Privilege escalation
Where: Local system
Solution Status: Vendor Patch

OS:SUSE Linux 10
SUSE Linux 10.1
SUSE Linux 9.3
SUSE Linux Enterprise Server 10
SuSE Linux Enterprise Server 8
SUSE Linux Enterprise Server 9
SuSE Linux Openexchange Server 4.x
SuSE Linux Standard Server 8
UnitedLinux 1.0

Software:Novell Open Enterprise Server 1.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-6101
CVE-2006-6102
CVE-2006-6103


Description:
SUSE has issued an update for XFree86 and Xorg. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges.

For more information:
SA23670

Solution:
Apply updated packages.

x86 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10...586/xorg-x11-server-7.2-30.4.i586.rpm
58a6c5df853248cf8b288c3b42418ed4

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10.../xorg-x11-server-6.9.0-50.30.i586.rpm
73150d439b17768c2a634b3a6d2bc9e0

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda...xorg-x11-server-6.8.2-100.10.i586.rpm
de6c0a54f56c216296ff9a7b3a3dc571

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/upda.../xorg-x11-server-6.8.2-30.10.i586.rpm
cb05dbcf305d096cfea12acc7d250483

Power PC Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/ppc/xorg-x11-server-7.2-30.4.ppc.rpm
af51406c70d92459c507718946883156

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10...c/xorg-x11-server-6.9.0-50.30.ppc.rpm
c93f29c703d5a9ab6c05f6348df42d3b

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda.../xorg-x11-server-6.8.2-100.10.ppc.rpm
122c81ed707559eb873a511ec7a381a1

x86-64 Platform:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10...4/xorg-x11-server-7.2-30.4.x86_64.rpm
2096f490f773d96e5a11cf9e715bdd74

SUSE LINUX 10.1:
ftp://ftp.suse.com/pub/suse/update/10...org-x11-server-6.9.0-50.30.x86_64.rpm
68ac3ff1bfa31483f016c62d72e934a3

SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/upda...rg-x11-server-6.8.2-100.10.x86_64.rpm
37cfc2641f53d9a70c8e437b58e2823f

SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/upda...org-x11-server-6.8.2-30.10.x86_64.rpm
864dc49e5a969a737efefc7c2a1fa3d6

Sources:

openSUSE 10.2:
ftp://ftp.suse.com/pub/suse/update/10.2/rpm/src/xorg-x11-server-7.2-30.4.src.rpm
7539d15ac32aa71a3dbbe23dd39854aa

Open Enterprise Server
http://support.novell.com/techcenter/psdb/3806664392b7217bd698fe6e5213851c.html

Novell Linux POS 9
http://support.novell.com/techcenter/psdb/3806664392b7217bd698fe6e5213851c.html

Novell Linux Desktop 9
http://support.novell.com/techcenter/psdb/3806664392b7217bd698fe6e5213851c.html

SuSE Linux Desktop 1.0
http://support.novell.com/techcenter/psdb/3806664392b7217bd698fe6e5213851c.html

SUSE SLES 9
http://support.novell.com/techcenter/psdb/3806664392b7217bd698fe6e5213851c.html

UnitedLinux 1.0
http://support.novell.com/techcenter/psdb/765b98b723b218b9c8a8e02d4064621a.html

SuSE Linux Openexchange Server 4
http://support.novell.com/techcenter/psdb/765b98b723b218b9c8a8e02d4064621a.html

SuSE Linux Enterprise Server 8
http://support.novell.com/techcenter/psdb/765b98b723b218b9c8a8e02d4064621a.html

SuSE Linux Standard Server 8
http://support.novell.com/techcenter/psdb/765b98b723b218b9c8a8e02d4064621a.html

SuSE Linux School Server
http://support.novell.com/techcenter/psdb/765b98b723b218b9c8a8e02d4064621a.html

SUSE LINUX Retail Solution 8
http://support.novell.com/techcenter/psdb/765b98b723b218b9c8a8e02d4064621a.html

SUSE SLES 10
http://support.novell.com/techcenter/psdb/8d278592fd99987cae177d85827bdf26.html

SUSE SLED 10
http://support.novell.com/techcenter/psdb/8d278592fd99987cae177d85827bdf26.html

Original Advisory:
http://www.novell.com/linux/security/advisories/2007_08_x.html

Other References:
SA23670:
http://secunia.com/advisories/23670/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 4
New vulnerabilities: 13
Updated advisories: 5

Less // 85 views
Red Hat update for kernel
Less // 85 views
Ubuntu update for bind9
Less // 74 views
Ubuntu update for ntp
Less // 77 views
Red Hat update for bind

8th Jan, 2009
New advisories: 24
New vulnerabilities: 99
Updated advisories: 26


Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Red Hat update for kernel // 70 views
2. Ubuntu update for bind9 // 69 views
3. Red Hat update for bind // 67 views
4. Ubuntu update for ntp // 61 views
5. SAP GUI TabOne ActiveX Control Caption List Buffer Overflow // 51 views
6. Drupal Project Module File Upload and Cross-Site Scripting // 38 views
7. Sun Java JDK / JRE Multiple Vulnerabilities // 34 views
8. Cisco Global Site Selector DNS Request Denial of Service // 32 views
9. SmbFTPD Long Command Processing Vulnerability // 31 views
10. NTP OpenSSL "EVP_VerifyFinal()" Spoofing Vulnerability // 30 views