Scientific Linux Security Update : X11 client libraries on SL6.x i386/x86_64 (20141014)

Medium Nessus Plugin ID 78841

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

Multiple integer overflow flaws, leading to heap-based buffer overflows, were found in the way various X11 client libraries handled certain protocol data. An attacker able to submit invalid protocol data to an X11 server via a malicious X11 client could use either of these flaws to potentially escalate their privileges on the system.
(CVE-2013-1981, CVE-2013-1982, CVE-2013-1983, CVE-2013-1984, CVE-2013-1985, CVE-2013-1986, CVE-2013-1987, CVE-2013-1988, CVE-2013-1989, CVE-2013-1990, CVE-2013-1991, CVE-2013-2003, CVE-2013-2062, CVE-2013-2064)

Multiple array index errors, leading to heap-based buffer out-of-bounds write flaws, were found in the way various X11 client libraries handled data returned from an X11 server. A malicious X11 server could possibly use this flaw to execute arbitrary code with the privileges of the user running an X11 client. (CVE-2013-1997, CVE-2013-1998, CVE-2013-1999, CVE-2013-2000, CVE-2013-2001, CVE-2013-2002, CVE-2013-2066)

A buffer overflow flaw was found in the way the XListInputDevices() function of X.Org X11's libXi runtime library handled signed numbers.
A malicious X11 server could possibly use this flaw to execute arbitrary code with the privileges of the user running an X11 client.
(CVE-2013-1995)

A flaw was found in the way the X.Org X11 libXt runtime library used uninitialized pointers. A malicious X11 server could possibly use this flaw to execute arbitrary code with the privileges of the user running an X11 client. (CVE-2013-2005)

Two stack-based buffer overflow flaws were found in the way libX11, the Core X11 protocol client library, processed certain user-specified files. A malicious X11 server could possibly use this flaw to crash an X11 client via a specially crafted file. (CVE-2013-2004)

The xkeyboard-config package has been upgraded to upstream version 2.11, which provides a number of bug fixes and enhancements over the previous version.

This update also fixes the following bugs :

- Previously, updating the mesa-libGL package did not update the libX11 package, although it was listed as a dependency of mesa-libGL. This bug has been fixed and updating mesa-libGL now updates all dependent packages as expected.

- Previously, closing a customer application could occasionally cause the X Server to terminate unexpectedly. After this update, the X Server no longer hangs when a user closes a customer application.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?cb540d84

Plugin Details

Severity: Medium

ID: 78841

File Name: sl_20141014_X11_client_libraries_on_SL6_x.nasl

Version: 1.4

Type: local

Agent: unix

Published: 2014/11/04

Updated: 2020/02/25

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:fermilab:scientific_linux:libX11, p-cpe:/a:fermilab:scientific_linux:libX11-common, p-cpe:/a:fermilab:scientific_linux:libX11-debuginfo, p-cpe:/a:fermilab:scientific_linux:libX11-devel, p-cpe:/a:fermilab:scientific_linux:libXcursor, p-cpe:/a:fermilab:scientific_linux:libXcursor-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXcursor-devel, p-cpe:/a:fermilab:scientific_linux:libXext, p-cpe:/a:fermilab:scientific_linux:libXext-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXext-devel, p-cpe:/a:fermilab:scientific_linux:libXfixes, p-cpe:/a:fermilab:scientific_linux:libXfixes-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXfixes-devel, p-cpe:/a:fermilab:scientific_linux:libXi, p-cpe:/a:fermilab:scientific_linux:libXi-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXi-devel, p-cpe:/a:fermilab:scientific_linux:libXinerama, p-cpe:/a:fermilab:scientific_linux:libXinerama-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXinerama-devel, p-cpe:/a:fermilab:scientific_linux:libXp, p-cpe:/a:fermilab:scientific_linux:libXp-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXp-devel, p-cpe:/a:fermilab:scientific_linux:libXrandr, p-cpe:/a:fermilab:scientific_linux:libXrandr-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXrandr-devel, p-cpe:/a:fermilab:scientific_linux:libXrender, p-cpe:/a:fermilab:scientific_linux:libXrender-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXrender-devel, p-cpe:/a:fermilab:scientific_linux:libXres, p-cpe:/a:fermilab:scientific_linux:libXres-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXres-devel, p-cpe:/a:fermilab:scientific_linux:libXt, p-cpe:/a:fermilab:scientific_linux:libXt-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXt-devel, p-cpe:/a:fermilab:scientific_linux:libXtst, p-cpe:/a:fermilab:scientific_linux:libXtst-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXtst-devel, p-cpe:/a:fermilab:scientific_linux:libXv, p-cpe:/a:fermilab:scientific_linux:libXv-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXv-devel, p-cpe:/a:fermilab:scientific_linux:libXvMC, p-cpe:/a:fermilab:scientific_linux:libXvMC-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXvMC-devel, p-cpe:/a:fermilab:scientific_linux:libXxf86dga, p-cpe:/a:fermilab:scientific_linux:libXxf86dga-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXxf86dga-devel, p-cpe:/a:fermilab:scientific_linux:libXxf86vm, p-cpe:/a:fermilab:scientific_linux:libXxf86vm-debuginfo, p-cpe:/a:fermilab:scientific_linux:libXxf86vm-devel, p-cpe:/a:fermilab:scientific_linux:libdmx, p-cpe:/a:fermilab:scientific_linux:libdmx-debuginfo, p-cpe:/a:fermilab:scientific_linux:libdmx-devel, p-cpe:/a:fermilab:scientific_linux:libxcb, p-cpe:/a:fermilab:scientific_linux:libxcb-debuginfo, p-cpe:/a:fermilab:scientific_linux:libxcb-devel, p-cpe:/a:fermilab:scientific_linux:libxcb-doc, p-cpe:/a:fermilab:scientific_linux:libxcb-python, p-cpe:/a:fermilab:scientific_linux:xcb-proto, p-cpe:/a:fermilab:scientific_linux:xkeyboard-config, p-cpe:/a:fermilab:scientific_linux:xkeyboard-config-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-proto-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-xtrans-devel, x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 2014/10/14

Vulnerability Publication Date: 2013/06/15

Reference Information

CVE: CVE-2013-1981, CVE-2013-1982, CVE-2013-1983, CVE-2013-1984, CVE-2013-1985, CVE-2013-1986, CVE-2013-1987, CVE-2013-1988, CVE-2013-1989, CVE-2013-1990, CVE-2013-1991, CVE-2013-1995, CVE-2013-1997, CVE-2013-1998, CVE-2013-1999, CVE-2013-2000, CVE-2013-2001, CVE-2013-2002, CVE-2013-2003, CVE-2013-2004, CVE-2013-2005, CVE-2013-2062, CVE-2013-2064, CVE-2013-2066