Beschreibung: | Summary: The remote host is missing an update for the 'X' package(s) announced via the SSA:2005-269-02 advisory.
Vulnerability Insight: New X.Org server packages are available for Slackware 10.0, 10.1, 10.2, and -current to fix a security issue. An integer overflow in the pixmap handling code may allow the execution of arbitrary code through a specially crafted pixmap. Slackware 10.2 was patched against this vulnerability before its release, but new server packages are being issued for Slackware 10.2 and -current using an improved patch, as there were some bug reports using certain programs.
More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database:
[link moved to references]
Here are the details from the Slackware 10.2 ChangeLog: +--------------------------+ patches/packages/x11-6.8.2-i486-4.tgz: Rebuilt with a modified patch for an earlier pixmap overflow issue. The patch released by X.Org was slightly different than the one that was circulated previously, and is an improved version. There have been reports that the earlier patch broke WINE and possibly some other programs. For more information, see: [link moved to references] (* Security fix *) patches/packages/x11-xdmx-6.8.2-i486-4.tgz: Patched and rebuilt. patches/packages/x11-xnest-6.8.2-i486-4.tgz: Patched and rebuilt. patches/packages/x11-xvfb-6.8.2-i486-4.tgz: Patched and rebuilt. +--------------------------+
Affected Software/OS: 'X' package(s) on Slackware 10.0, Slackware 10.1, Slackware 10.2, Slackware current.
Solution: Please install the updated package(s).
CVSS Score: 5.1
CVSS Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P
|