Release date: 2011-10-06
Updated on: 2011-10-10
Affected Systems:
RedHat Enterprise Linux
X.org X11R6 6.x
X.org X11R6 5.1
X.org X11R6 4.0
X.org X11R7 7.x
X.org X11R7 1.1.1
X.org X11R7 1.0.2
X.org X11R7 1.0.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50002
Cve id: CVE-2011-4818, CVE-2011-4819
X. Org is the open-source implementation of X Window System by X. Org Foundation.
X. Org X11 has local permission escalation and Memory leakage vulnerabilities. Remote attackers can exploit these vulnerabilities to execute arbitrary code with higher permissions, causing the affected computer to crash or obtain sensitive information.
Multiple GLX calls lack correct input filtering. Attackers who can access GLX calls Cause X server to crash or execute arbitrary code in it.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 740954
Https://www.redhat.com/security/data/cve/CVE-2010-4819.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
X.org
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.x.org/