There's a buffer overflow in XFree86 allowing local attackers to gain root privileges. Here's the patch, ftp://ftp.xfree86.org/pub/XFree86/4.3.0/fixes/fontfile.diff the advisory

http://www.idefense.com/application/poi/display?id=72&type=vulnerabilities&flashstatus=false and a demo exploit also already has been published. I think it would be a good idea if someone could apply the patch to the dri cvs (applies with some fuzz and offset), if it is vulnerable.

Roland



-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
--
_______________________________________________
Dri-devel mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/dri-devel

Reply via email to