首页 -> 安全研究

安全研究

安全漏洞
XFree86 MIT-SHM共享内存访问漏洞

发布日期:2002-10-24
更新日期:2002-10-29

受影响系统:
Caldera OpenUnix 8.0
Caldera UnixWare 7.1.1
SGI IRIX 6.5.9m
SGI IRIX 6.5.9f
SGI IRIX 6.5.9
SGI IRIX 6.5.8m
SGI IRIX 6.5.8f
SGI IRIX 6.5.8
SGI IRIX 6.5.7m
SGI IRIX 6.5.7f
SGI IRIX 6.5.7
SGI IRIX 6.5.6m
SGI IRIX 6.5.6f
SGI IRIX 6.5.6
SGI IRIX 6.5.5m
SGI IRIX 6.5.5f
SGI IRIX 6.5.5
SGI IRIX 6.5.4m
SGI IRIX 6.5.4f
SGI IRIX 6.5.4
SGI IRIX 6.5.3m
SGI IRIX 6.5.3f
SGI IRIX 6.5.3
SGI IRIX 6.5.2m
SGI IRIX 6.5.2f
SGI IRIX 6.5.2
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17
SGI IRIX 6.5.16 m
SGI IRIX 6.5.16
SGI IRIX 6.5.15m
SGI IRIX 6.5.15f
SGI IRIX 6.5.15
SGI IRIX 6.5.14m
SGI IRIX 6.5.14f
SGI IRIX 6.5.14
SGI IRIX 6.5.13m
SGI IRIX 6.5.13f
SGI IRIX 6.5.13
SGI IRIX 6.5.12m
SGI IRIX 6.5.12f
SGI IRIX 6.5.12
SGI IRIX 6.5.11m
SGI IRIX 6.5.11f
SGI IRIX 6.5.11
SGI IRIX 6.5.10m
SGI IRIX 6.5.10f
SGI IRIX 6.5.10
SGI IRIX 6.5.1
SGI IRIX 6.5
XFree86 X11R6 4.2.1
XFree86 X11R6 4.1.0
XFree86 X11R6 4.0.2-11
XFree86 X11R6 4.0.1
XFree86 X11R6 4.0
XFree86 X11R6 4.0.3
    - RedHat Linux 7.1
XFree86 X11R6 4.1-11
    - Caldera Open Linux Workstation 3.1.1
    - Caldera Open Linux Server 3.1.1
XFree86 X11R6 4.2.0
    - SuSE Linux 8.0
不受影响系统:
SGI IRIX 6.5.18
XFree86 X11R6 4.2.1 Errata
描述:
BUGTRAQ  ID: 4396
CVE(CAN) ID: CVE-2002-0164

XFree86 MIT-SHM扩展为X进程提供SYSTEM V共享内存。如为XImages提供共享内存机制,ximage接口的实际图象数据存储在共享内存段,这样就不用通过XLib中间进程通信通道进行图象存储操作,对于处理大型图象,使用这个功能可以提供系统性能。

XFree86 MIT-SHM扩展存在访问控制问题,本地攻击者可以利用这个漏洞读/写任意共享内存,提升权限。

XFree86 MIT-SHM扩展存在问题允许本地X用户读和写系统中任意共享内存段地址,使用精心构建的地址覆盖共享内存段,使的非特权X用户可以以XFree86进程权限在系统上执行任意指令。

<*来源:Roberto Zunino.
  
  链接:ftp://patches.sgi.com/support/free/security/advisories/20021001-01-P
        http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000533
        http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000529
        http://www.caldera.com/support/security/advisories/CSSA-2002-009.0.txt
        ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.14
        ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:06.asc
*>

建议:
厂商补丁:

Caldera
-------
Caldera已经为此发布了两个安全公告(CSSA-2002-SCO.14)和(CSSA-2002-009.0):
CSSA-2002-SCO.14:Open UNIX 8.0.0 UnixWare 7.1.1 : X server allows access to any shared memory on the system
链接:ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.14

CSSA-2002-009.0:Linux: X server allows access to any shared memory on the system
链接:http://www.caldera.com/support/security/advisories/CSSA-2002-009.0.txt

补丁下载:

Caldera UnixWare 7.1.1:

Caldera Upgrade xserver.711b.pkg
ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.14/xserver.711b.pkg

Caldera OpenUnix 8.0:

Caldera Upgrade xserver.800a.pkg
ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.14/xserver.800a.pkg

Caldera RPM XFree86-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-4.1-12.i386.rpm

Caldera RPM XFree86-addons-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-addons-4.1-12.i386.rpm

Caldera RPM XFree86-setup-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-setup-4.1-12.i386.rpm

Caldera RPM XFree86-twm-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-twm-4.1-12.i386.rpm

Caldera RPM XFree86-xdm-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-xdm-4.1-12.i386.rpm

Caldera RPM XFree86-Xnest-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-Xnest-4.1-12.i386.rpm

Caldera RPM XFree86-Xprt-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-Xprt-4.1-12.i386.rpm

Caldera RPM XFree86-xsm-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-xsm-4.1-12.i386.rpm

Caldera RPM XFree86-xterm-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-xterm-4.1-12.i386.rpm

Caldera RPM XFree86-Xvfb-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-Xvfb-4.1-12.i386.rpm

Caldera RPM XFree86-4.1-12.src.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/SRPMS/XFree86-4.1-12.src.rpm

Caldera RPM XFree86-config-eg-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-config-eg-4.1-12.i386.rpm

Caldera RPM XFree86-contrib-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-contrib-4.1-12.i386.rpm

Caldera RPM XFree86-devel-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-devel-4.1-12.i386.rpm

Caldera RPM XFree86-devel-prof-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-devel-prof-4.1-12.i386.rpm

Caldera RPM XFree86-devel-static-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-devel-static-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-100dpi-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-fonts-100dpi-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-fonts-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-75dpi-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-fonts-75dpi-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-cyrillic-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-fonts-cyrillic-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-extra-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-fonts-extra-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-scale-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-fonts-scale-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-speedo-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-fonts-speedo-4.1-12.i386.rpm

Caldera RPM XFree86-fontserver-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-fontserver-4.1-12.i386.rpm

Caldera RPM XFree86-imake-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-imake-4.1-12.i386.rpm

Caldera RPM XFree86-libs-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-libs-4.1-12.i386.rpm

Caldera RPM XFree86-misc-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-misc-4.1-12.i386.rpm

Caldera RPM XFree86-pex-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-pex-4.1-12.i386.rpm

Caldera RPM XFree86-programs-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-programs-4.1-12.i386.rpm

Caldera RPM XFree86-server-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-server-4.1-12.i386.rpm

Caldera RPM XFree86-setup-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-setup-4.1-12.i386.rpm

Caldera RPM XFree86-twm-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-twm-4.1-12.i386.rpm

Caldera RPM XFree86-xdm-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-xdm-4.1-12.i386.rpm

Caldera RPM XFree86-Xnest-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-Xnest-4.1-12.i386.rpm

Caldera RPM XFree86-Xprt-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-Xprt-4.1-12.i386.rpm

Caldera RPM XFree86-xsm-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-xsm-4.1-12.i386.rpm

Caldera RPM XFree86-xterm-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-xterm-4.1-12.i386.rpm

Caldera RPM XFree86-Xvfb-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/RPMS/XFree86-Xvfb-4.1-12.i386.rpm

Caldera RPM XFree86-4.1-12.src.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Server/current/SRPMS/XFree86-4.1-12.src.rpm

Caldera RPM XFree86-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-4.1-12.i386.rpm

Caldera RPM XFree86-addons-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-addons-4.1-12.i386.rpm

Caldera RPM XFree86-config-eg-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-config-eg-4.1-12.i386.rpm

Caldera RPM XFree86-contrib-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-contrib-4.1-12.i386.rpm

Caldera RPM XFree86-devel-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-devel-4.1-12.i386.rpm

Caldera RPM XFree86-devel-prof-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-devel-prof-4.1-12.i386.rpm

Caldera RPM XFree86-devel-static-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-devel-static-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-100dpi-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-fonts-100dpi-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-fonts-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-75dpi-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-fonts-75dpi-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-cyrillic-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-fonts-cyrillic-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-extra-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-fonts-extra-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-scale-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-fonts-scale-4.1-12.i386.rpm

Caldera RPM XFree86-fonts-speedo-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-fonts-speedo-4.1-12.i386.rpm

Caldera RPM XFree86-fontserver-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-fontserver-4.1-12.i386.rpm

Caldera RPM XFree86-imake-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-imake-4.1-12.i386.rpm

Caldera RPM XFree86-libs-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-libs-4.1-12.i386.rpm

Caldera RPM XFree86-misc-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-misc-4.1-12.i386.rpm

Caldera RPM XFree86-pex-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-pex-4.1-12.i386.rpm

Caldera RPM XFree86-programs-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-programs-4.1-12.i386.rpm

Caldera RPM XFree86-server-4.1-12.i386.rpm
ftp://ftp.caldera.com/pub/updates/OpenLinux/3.1.1/Workstation/current/RPMS/XFree86-server-4.1-12.i386.rpm

Conectiva
---------
Conectiva已经为此发布了两个安全公告(CLA-2002:529)(CLA-2002:533):
CLA-2002:529:XFree86
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000529
CLA-2002:533:XFree86
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000533

补丁下载:

ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-apm-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-ark-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-ati-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-ati-dri-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-bench-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-chips-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-cirrus-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-common-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-config-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-cyrix-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-devel-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-devel-static-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-doc-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-doc-html-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-dps-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-fbdev-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-GL-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-GL-devel-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-glide-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-glint-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-i128-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-i740-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-i810-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-i810-dri-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-libs-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-libs-common-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-libs-Xaw-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-libs-Xaw6-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-manpages-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-mga-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-mga-dri-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-minimal-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-misc-locales-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-afb-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-cfb-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-codeconv-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-extended-input-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-fb-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-fb-lowcolor-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-fb-multi-depths-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-freetype-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-xaa-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-modules-xtt-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-neomagic-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-nv-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-progs-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-proxy-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-rendition-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-s3-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-s3virge-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-savage-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-Server-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-Server-common-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-siliconmotion-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-sis-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-sis-dri-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-tdfx-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-tdfx-dri-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-tga-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-trident-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-tseng-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-twm-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-vesa-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-vga-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-vmware-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-xdm-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-xfs-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-xkb-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-Xnest-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-Xprt-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/XFree86-Xvfb-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/xterm-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/freetype2-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/freetype2-devel-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/freetype2-devel-static-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/rstart-4.2.0-21U80_2cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/SRPMS/XFree86-4.2.0-21U80_2cl.src.rpm

Conectiva Linux version 6.0及以上版本的用户可以使用apt进行RPM包的更新:

- 把以下的文本行加入到/etc/apt/sources.list文件中:
  
rpm [cncbr] ftp://atualizacoes.conectiva.com.br 6.0/conectiva updates

(如果你不是使用6.0版本,用合适的版本号代替上面的6.0)

- 执行:                 apt-get update
- 更新以后,再执行:     apt-get upgrade

FreeBSD
-------
FreeBSD已经为此发布了一个安全公告(FreeBSD-SN-02:06)以及相应补丁:
FreeBSD-SN-02:06:Topic:security issues in ports
链接:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:06.asc

SGI
---
SGI已经为此发布了一个安全公告(20021001-01-P)以及相应补丁:
20021001-01-P:X Windows zlib/MIT-SHM/huge font DoS vulnerabilities
链接:ftp://patches.sgi.com/support/free/security/advisories/20021001-01-P

补丁下载:

SGI Patch 4709
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.13 f:

SGI Patch 4710
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.14 m:

SGI Patch 4648
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.14 f:

SGI Patch 4649
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.15 m:

SGI Patch 4648
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.15 f:

SGI Patch 4649
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.16 m:

SGI Patch 4663
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.16 f:

SGI Patch 4664
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.17 m:

SGI Patch 4757
ftp://patches.sgi.com/support/free/security/patches/

SGI IRIX 6.5.17 f:

SGI Patch 4758
ftp://patches.sgi.com/support/free/security/patches/

浏览次数:3732
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障