[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2014-0018 -- Oracle libXfont

ID: oval:org.secpod.oval:def:1500356Date: (C)2014-07-08   (M)2023-12-07
Class: PATCHFamily: unix




Updated libXfont packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having important security impact. A Common Vulnerability Scoring System base score, which gives a detailed severity rating, is available from the CVE link in the References section. The libXfont packages provide the X.Org libXfont runtime library. X.Org is an open source implementation of the X Window System. A stack-based buffer overflow flaw was found in the way the libXfont library parsed Glyph Bitmap Distribution Format fonts. A malicious, local user could exploit this issue to potentially execute arbitrary code with the privileges of the X.Org server. Users of libXfont should upgrade to these updated packages, which contain a backported patch to resolve this issue. All running X.Org server instances must be restarted for the update to take effect.

Platform:
Oracle Linux 6
Product:
libXfont
Reference:
ELSA-2014-0018
CVE-2013-6462
CVE    1
CVE-2013-6462
CPE    25
cpe:/a:x:libxfont
cpe:/o:oracle:linux:6
cpe:/a:x:libxfont:1.2.9
cpe:/a:x:libxfont:1.2.5
...

© SecPod Technologies