![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.1.10.2015.0073 |
Category: | Mageia Linux Local Security Checks |
Title: | Mageia: Security Advisory (MGASA-2015-0073) |
Summary: | The remote host is missing an update for the 'x11-server' package(s) announced via the MGASA-2015-0073 advisory. |
Description: | Summary: The remote host is missing an update for the 'x11-server' package(s) announced via the MGASA-2015-0073 advisory. Vulnerability Insight: Updated x11-server packages fix security vulnerability: Olivier Fourdan from Red Hat has discovered a protocol handling issue in the way the X server code base handles the XkbSetGeometry request, where the server trusts the client to send valid string lengths. A malicious client with string lengths exceeding the request length can cause the server to copy adjacent memory data into the XKB structs. This data is then available to the client via the XkbGetGeometry request. This can lead to information disclosure issues, as well as possibly a denial of service if a similar request can cause the server to crash (CVE-2015-0255). Affected Software/OS: 'x11-server' package(s) on Mageia 4. Solution: Please install the updated package(s). CVSS Score: 6.4 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2015-0255 BugTraq ID: 72578 http://www.securityfocus.com/bid/72578 Debian Security Information: DSA-3160 (Google Search) http://www.debian.org/security/2015/dsa-3160 https://security.gentoo.org/glsa/201504-06 http://www.mandriva.com/security/advisories?name=MDVSA-2015:119 RedHat Security Advisories: RHSA-2015:0797 http://rhn.redhat.com/errata/RHSA-2015-0797.html SuSE Security Announcement: openSUSE-SU-2015:0337 (Google Search) http://lists.opensuse.org/opensuse-updates/2015-02/msg00085.html SuSE Security Announcement: openSUSE-SU-2015:0338 (Google Search) http://lists.opensuse.org/opensuse-updates/2015-02/msg00086.html http://www.ubuntu.com/usn/USN-2500-1 |
Copyright | Copyright (C) 2022 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |