SCIENTIFIC-LINUX-ERRATA Archives

December 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 9 Dec 2013 16:02:42 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (59 lines)
Synopsis:          Low: xorg-x11-server security and bug fix update
Advisory ID:       SLSA-2013:1620-2
Issue Date:        2013-11-21
CVE Numbers:       CVE-2013-1940
--

A flaw was found in the way the X.org X11 server registered new hot
plugged devices. If a local user switched to a different session and
plugged in a new device, input from that device could become available in
the previous session, possibly leading to information disclosure.
(CVE-2013-1940)

This update also fixes the following bugs:

* A previous upstream patch modified the Xephyr X server to be resizeable,
however, it did not enable the resize functionality by default. As a
consequence, X sandboxes were not resizeable on Scientific Linux 6.4 and
later. This update enables the resize functionality by default so that X
sandboxes can now be resized as expected.

* In Scientific Linux 6, the X Security extension (XC-SECURITY) has been
disabled and replaced by X Access Control Extension (XACE). However, XACE
does not yet include functionality that was previously available in XC-
SECURITY. With this update, XC-SECURITY is enabled in the xorg-x11-server
spec file on Scientific Linux 6.

* Upstream code changes to extension initialization accidentally disabled
the GLX extension in Xvfb (the X virtual frame buffer), rendering headless
3D applications not functional. An upstream patch to this problem has been
backported so the GLX extension is enabled again, and applications relying
on this extension work as expected.
--

SL6
  x86_64
    xorg-x11-server-Xephyr-1.13.0-23.sl6.x86_64.rpm
    xorg-x11-server-Xorg-1.13.0-23.sl6.x86_64.rpm
    xorg-x11-server-common-1.13.0-23.sl6.x86_64.rpm
    xorg-x11-server-debuginfo-1.13.0-23.sl6.x86_64.rpm
    xorg-x11-server-Xdmx-1.13.0-23.sl6.x86_64.rpm
    xorg-x11-server-Xnest-1.13.0-23.sl6.x86_64.rpm
    xorg-x11-server-Xvfb-1.13.0-23.sl6.x86_64.rpm
    xorg-x11-server-debuginfo-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-devel-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-devel-1.13.0-23.sl6.x86_64.rpm
  i386
    xorg-x11-server-Xephyr-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-Xorg-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-common-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-debuginfo-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-Xdmx-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-Xnest-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-Xvfb-1.13.0-23.sl6.i686.rpm
    xorg-x11-server-devel-1.13.0-23.sl6.i686.rpm
  noarch
    xorg-x11-server-source-1.13.0-23.sl6.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2