Scientific Linux Security Update : xorg-x11-server-utils on SL5.x, SL6.x i386/x86_64

This script is Copyright (C) 2012-2017 Tenable Network Security, Inc.

Synopsis :

The remote Scientific Linux host is missing a security update.

Description :

A flaw was found in the X.Org X server resource database utility,
xrdb. Certain variables were not properly sanitized during the launch
of a user's graphical session, which could possibly allow a remote
attacker to execute arbitrary code with root privileges, if they were
able to make the display manager execute xrdb with a specially crafted
X client hostname. For example, by configuring the hostname on the
target system via a crafted DHCP reply, or by using the X Display
Manager Control Protocol (XDMCP) to connect to that system from a host
that has a special DNS name. (CVE-2011-0465)

All running X.Org server instances must be restarted for this update
to take effect.

See also :

Solution :

Update the affected xorg-x11-server-utils package.

Risk factor :

High / CVSS Base Score : 9.3

Family: Scientific Linux Local Security Checks

Nessus Plugin ID: 61016 ()

Bugtraq ID:

CVE ID: CVE-2011-0465

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now