Description: Red Hat has issued an update for xorg-x11 and xorg-x11-xfs. This fixes a vulnerability, which can be exploited by malicious, local users to perform actions with escalated privileges.
The vulnerability is caused due to a race condition within the handling of temporary files when the xfs font server startup script is executed. This can be exploited to change the permissions of arbitrary files.
Solution: Updated packages are available from Red Hat Network. http://rhn.redhat.com
Provided and/or discovered by: An anonymous person, reported via iDefense.
Changelog: 2007-07-13: Added link to iDefense advisory.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.