SciLinux: CVE-2008-0006 libXfont SL5.x i386/x86_64
Summary
Date: Fri, 18 Jan 2008 12:45:18 -0600Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for libXfont on SL5.x i386/x86_64Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Important: libXfont security updateIssue date: 2008-01-17CVE Names: CVE-2008-0006A heap based buffer overflow flaw was found in the way the X.Org serverhandled malformed font files. A malicious local user could exploit thisissue to potentially execute arbitrary code with the privileges of theX.Org server. (CVE-2008-0006)SL 5.x SRPMS:libXfont-1.2.2-1.0.3.el5_1.src.rpm i386:libXfont-1.2.2-1.0.3.el5_1.i386.rpmlibXfont-devel-1.2.2-1.0.3.el5_1.i386.rpm x86_64:libXfont-1.2.2-1.0.3.el5_1.i386.rpmlibXfont-1.2.2-1.0.3.el5_1.x86_64.rpmlibXfont-devel-1.2.2-1.0.3.el5_1.i386.rpmlibXfont-devel-1.2.2-1.0.3.el5_1.x86_64.rpm-Connie Sieh-Troy Dawson