XFree86 4.1.0缺少authDir的未认证xdm连接漏洞

漏洞信息详情

XFree86 4.1.0缺少authDir的未认证xdm连接漏洞

漏洞简介

将authComplain变量设为false的xdm存在漏洞。任意攻击者可以利用该漏洞在xdm auth目录不存在的情况下连接X服务器。

漏洞公告

XFree86 has released version 4.2.0 which addresses this issue.
Red Hat updates are available.
Sun Linux updates have been released to correct this issue.
XFree86 X11R6 4.0

  • XFree86 X11R6 4.2.0 installation scriptThis is just the installation script. You must acquire the platform specific binary for this distribution from ftp://ftp.xfree86.org/pub/XFree86/4.2.0/binaries/ or
    http://ftp.xfree86.org/pub/XFree86/4.2.0/binaries/ . To determine which distribution you need to download, obtain the installation scr
    ftp://ftp.xfree86.org/pub/XFree86/4.2.0/Xinstall.sh

XFree86 X11R6 4.0.1

  • XFree86 X11R6 4.2.0 installation scriptThis is just the installation script. You must acquire the platform specific binary for this distribution from ftp://ftp.xfree86.org/pub/XFree86/4.2.0/binaries/ or
    http://ftp.xfree86.org/pub/XFree86/4.2.0/binaries/ . To determine which distribution you need to download, obtain the installation scr
    ftp://ftp.xfree86.org/pub/XFree86/4.2.0/Xinstall.sh

XFree86 X11R6 4.0.3

  • XFree86 X11R6 4.2.0 installation scriptThis is just the installation script. You must acquire the platform specific binary for this distribution from ftp://ftp.xfree86.org/pub/XFree86/4.2.0/binaries/ or
    http://ftp.xfree86.org/pub/XFree86/4.2.0/binaries/ . To determine which distribution you need to download, obtain the installation scr
    ftp://ftp.xfree86.org/pub/XFree86/4.2.0/Xinstall.sh

XFree86 X11R6 4.1 .0

  • XFree86 X11R6 4.2.0 installation scriptThis is just the installation script. You must acquire the platform specific binary for this distribution from ftp://ftp.xfree86.org/pub/XFree86/4.2.0/binaries/ or
    http://ftp.xfree86.org/pub/XFree86/4.2.0/binaries/ . To determine which distribution you need to download, obtain the installation scr
    ftp://ftp.xfree86.org/pub/XFree86/4.2.0/Xinstall.sh

Sun Linux 5.0.6

参考网址

来源: XF
名称: xfree86-xdm-unauth-access(11389)
链接:http://www.iss.net/security_center/static/11389.php

来源: wuarchive.wustl.edu
链接:http://wuarchive.wustl.edu/mirrors/NetBSD/NetBSD-current/xsrc/xfree/xc/programs/Xserver/hw/xfree86/CHANGELOG

来源: REDHAT
名称: RHSA-2003:065
链接:http://www.redhat.com/support/errata/RHSA-2003-065.html

来源: REDHAT
名称: RHSA-2003:064
链接:http://www.redhat.com/support/errata/RHSA-2003-064.html

来源: SUNALERT
名称: 55602
链接:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55602

来源: CONECTIVA
名称: CLA-2002:533
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000533

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享