XFree86 Font Information File Buffer Overflow Vulnerability

Solution:
The XFree86 Project has released a patch dealing with this issue.

SCO has released advisory SCOSA-2004.2 and updates to address this issue. Please see the referenced advisory for further details regarding obtaining and applying appropriate updates.

IBM have released an updated advisory (2004-06-08 - A buffer overflow exists in the X server.) and APAR fixes to address this issue. Affected users are advised to apply the appropriate APARs as soon as possible. Further information regarding obtaining and applying these APARs can be found in the referenced advisory.

SGI has released an advisory 20040203-01-U to address this and other issues in SGI ProPack 2.4 and ProPack 2.3. Please see the referenced advisory for more information. Fixes are available below.

Turbolinux have released an advisory (TLSA-2004-5) and fixes to address this issue. Affected users are advised to apply the appropriate updates as soon as possible. Further information regarding obtaining and applying these updates can be found in the referenced advisory.

OpenBSD Project has released fixes to address this issue. Fixes are linked below.

Red Hat has released an advisory (RHSA-2004:060-16) and fixes to address this issue in enterprise products. Customers who are subscribed to the Red Hat Network may run "up2date" to obtain fixes. Further details pertaining to obtaining and applying appropriate fixes can be found in the referenced advisory.

Red Hat has released a Fedora advisory (FEDORA-2004-069) and fixes to address this issue. Users who are running Fedora may run "up2date" to obtain fixes. Further details pertaining to obtaining and applying appropriate fixes can be found in the referenced advisory.

Mandrake has released an advisory (MDKSA-2004:012) and fixes to address this issue. Further details pertaining to obtaining and applying appropriate fixes can be found in the referenced advisory.

Immunix have released an advisory (IMNX-2004-73-002-01) and fixes to address this issue. Customers who are running Immunix 7.3 may run "up2date -u", to obtain fixes. Further details pertaining to obtaining and applying appropriate fixes can be found in the referenced advisory.

Slackware have released an advisory (SSA:2004-043-02) and fixes to address this issue. Please see referenced advisory for further details regarding the application of relevant fixes.

Gentoo has released advisory GLSA 200402-02 dealing with this issue. See the advisory for details on upgrading.

RedHat has released an advisory (RHSA-2004:059-01) to address this issue. See the referenced advisory for links to fixed packages.

Debian has released an advisory (DSA 443-1) and fixes to address this issue. See the referenced advisory for fix information.

Conectiva advisory CLA-2004:821 has bee released dealing with this issue. Please see the reference section for more information.

SuSE has released advisory SuSE-SA:2004:006 to address this issue. Please see the attached advisory for details on obtaining and applying fixes.

HP has released an advisory (HPSBUX01018) with fixes to address this issue. The advisory can be obtained from the following location, however, IT resource center authentication credentials are required:

http://your.hp.com/m/S.asp?HB13370677735X3451007X362981

The XFree86 Project has released version 4.3.0.2 to address this issue. This version is available from CVS, or via patches from version 4.3.0 to 4.3.0.1, and then from 4.3.0.1 to 4.3.0.2.

Fedora Legacy has released advisory FLSA-2005:2314 dealing with this and other issues for the Fedora Core 1 and RedHat Linux packages. Please see the referenced advisory for more information.

Sun has released Sun Alert ID: 57768 dealing with this and other issues. Please see the referenced advisory for more details. Please note that the Solaris 8 patch is not yet available.

Avaya has released advisory ASA-2005-113 and fixes for this issue. Please see the referenced advisory for additional details.


OpenBSD OpenBSD 3.4

Sun Solaris 7.0

IBM AIX 5.1

Sun Solaris 9

IBM AIX 5.2

OpenBSD OpenBSD 3.3

Sun Solaris 9_x86

Sun Solaris 7.0_x86

HP HP-UX 11.0 4
  • HP PHSS_30586
    Patch is available from: HP-UX Security Patch Matrix

  • HP PHSS_30706
    Patch is available from: HP-UX Security Patch Matrix


HP HP-UX 11.0
  • HP PHSS_30181
    Patch is available from: HP-UX Security Patch Matrix

  • HP PHSS_30477
    Patch is available from: HP-UX Security Patch Matrix


HP HP-UX 11.11
  • HP PHSS_30173
    Patch is available from: HP-UX Security Patch Matrix

  • HP PHSS_30478
    Patch is available from: HP-UX Security Patch Matrix


HP HP-UX 11.22
  • HP PHSS_30172
    Patch is available from: HP-UX Security Patch Matrix

  • HP PHSS_30479
    Patch is available from: HP-UX Security Patch Matrix


HP HP-UX 11.23
  • HP PHSS_30171
    Patch is available from: HP-UX Security Patch Matrix

  • HP PHSS_30480
    Patch is available from: HP-UX Security Patch Matrix


SGI ProPack 2.3

SGI ProPack 2.4

XFree86 X11R6 4.1 .0

XFree86 X11R6 4.2 .0

XFree86 X11R6 4.2.1

XFree86 X11R6 4.3 .0

IBM AIX 4.3.3


 

Privacy Statement
Copyright 2010, SecurityFocus