Scientific Linux 安全更新:SL6.x i386/x86_64 中的 Core X11 客户端

medium Nessus 插件 ID 65563

简介

远程 Scientific Linux 主机缺少一个或多个安全更新。

描述

已发现 x11perfcomp 实用工具在其 PATH 环境变量中包含当前工作目录。在受攻击者控制的目录中运行 x11perfcomp 将导致以运行 x11perfcomp 的用户的权限执行任意代码。(CVE-2011-2504)

通过此更新,xorg-x11-utils 和 xorg-x11-server-utils 程序包也已升级到上游版本 7.5,xorg-x11-apps 程序包已升级到上游版本 7.6,其提供了对之前版本的多项缺陷补丁和增强。

*xorg ABI 通过此更新变更,X.org ABI 中的视频驱动程序发生了变更。此变更将需要兼容的驱动程序。
任何使用 SL 随附的驱动程序的用户应该没有问题。
任何使用来自 nVidia、ATI 或 ELRepo 等外部源的驱动程序的用户应确保加载了兼容的驱动程序。更新系统之前,请确保使用最新的兼容的驱动程序。
--

解决方案

更新受影响的数据包。

另见

http://www.nessus.org/u?a04fd62e

插件详情

严重性: Medium

ID: 65563

文件名: sl_20130221_Core_X11_clients_on_SL6_x.nasl

版本: 1.8

类型: local

代理: unix

发布时间: 2013/3/15

最近更新时间: 2021/1/14

支持的传感器: Nessus Agent, Nessus

风险信息

VPR

风险因素: Medium

分数: 5.9

CVSS v2

风险因素: Medium

基本分数: 6.9

矢量: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

漏洞信息

CPE: p-cpe:/a:fermilab:scientific_linux:libx11, p-cpe:/a:fermilab:scientific_linux:libx11-common, p-cpe:/a:fermilab:scientific_linux:libx11-devel, p-cpe:/a:fermilab:scientific_linux:libxscrnsaver, p-cpe:/a:fermilab:scientific_linux:libxscrnsaver-devel, p-cpe:/a:fermilab:scientific_linux:libxau, p-cpe:/a:fermilab:scientific_linux:libxau-devel, p-cpe:/a:fermilab:scientific_linux:libxaw, p-cpe:/a:fermilab:scientific_linux:libxaw-devel, p-cpe:/a:fermilab:scientific_linux:libxcomposite, p-cpe:/a:fermilab:scientific_linux:libxcomposite-devel, p-cpe:/a:fermilab:scientific_linux:libxcursor, p-cpe:/a:fermilab:scientific_linux:libxcursor-devel, p-cpe:/a:fermilab:scientific_linux:libxdamage, p-cpe:/a:fermilab:scientific_linux:libxdamage-devel, p-cpe:/a:fermilab:scientific_linux:libxdmcp, p-cpe:/a:fermilab:scientific_linux:libxdmcp-devel, p-cpe:/a:fermilab:scientific_linux:libxevie, p-cpe:/a:fermilab:scientific_linux:libxevie-devel, p-cpe:/a:fermilab:scientific_linux:libxext, p-cpe:/a:fermilab:scientific_linux:libxext-devel, p-cpe:/a:fermilab:scientific_linux:libxfixes, p-cpe:/a:fermilab:scientific_linux:libxfixes-devel, p-cpe:/a:fermilab:scientific_linux:libxfont, p-cpe:/a:fermilab:scientific_linux:libxfont-devel, p-cpe:/a:fermilab:scientific_linux:libxft, p-cpe:/a:fermilab:scientific_linux:libxft-devel, p-cpe:/a:fermilab:scientific_linux:libxi, p-cpe:/a:fermilab:scientific_linux:libxi-devel, p-cpe:/a:fermilab:scientific_linux:libxinerama, p-cpe:/a:fermilab:scientific_linux:libxinerama-devel, p-cpe:/a:fermilab:scientific_linux:libxmu, p-cpe:/a:fermilab:scientific_linux:libxmu-devel, p-cpe:/a:fermilab:scientific_linux:libxpm, p-cpe:/a:fermilab:scientific_linux:libxpm-devel, p-cpe:/a:fermilab:scientific_linux:libxrandr, p-cpe:/a:fermilab:scientific_linux:libxrandr-devel, p-cpe:/a:fermilab:scientific_linux:libxrender, p-cpe:/a:fermilab:scientific_linux:libxrender-devel, p-cpe:/a:fermilab:scientific_linux:libxres, p-cpe:/a:fermilab:scientific_linux:libxres-devel, p-cpe:/a:fermilab:scientific_linux:libxt, p-cpe:/a:fermilab:scientific_linux:libxt-devel, p-cpe:/a:fermilab:scientific_linux:libxtst, p-cpe:/a:fermilab:scientific_linux:libxtst-devel, p-cpe:/a:fermilab:scientific_linux:libxv, p-cpe:/a:fermilab:scientific_linux:libxv-devel, p-cpe:/a:fermilab:scientific_linux:libxvmc, p-cpe:/a:fermilab:scientific_linux:libxvmc-devel, p-cpe:/a:fermilab:scientific_linux:libxxf86dga, p-cpe:/a:fermilab:scientific_linux:libxxf86dga-devel, p-cpe:/a:fermilab:scientific_linux:libxxf86misc, p-cpe:/a:fermilab:scientific_linux:libxxf86misc-devel, p-cpe:/a:fermilab:scientific_linux:libxxf86vm, p-cpe:/a:fermilab:scientific_linux:libxxf86vm-devel, p-cpe:/a:fermilab:scientific_linux:libpciaccess, p-cpe:/a:fermilab:scientific_linux:libpciaccess-devel, p-cpe:/a:fermilab:scientific_linux:libxcb, p-cpe:/a:fermilab:scientific_linux:libxcb-devel, p-cpe:/a:fermilab:scientific_linux:libxcb-doc, p-cpe:/a:fermilab:scientific_linux:libxcb-python, p-cpe:/a:fermilab:scientific_linux:mesa-demos, p-cpe:/a:fermilab:scientific_linux:mesa-dri-drivers, p-cpe:/a:fermilab:scientific_linux:mesa-dri-filesystem, p-cpe:/a:fermilab:scientific_linux:mesa-dri1-drivers, p-cpe:/a:fermilab:scientific_linux:mesa-libgl, p-cpe:/a:fermilab:scientific_linux:mesa-libgl-devel, p-cpe:/a:fermilab:scientific_linux:mesa-libglu, p-cpe:/a:fermilab:scientific_linux:mesa-libglu-devel, p-cpe:/a:fermilab:scientific_linux:mesa-libosmesa, p-cpe:/a:fermilab:scientific_linux:mesa-libosmesa-devel, p-cpe:/a:fermilab:scientific_linux:mtdev, p-cpe:/a:fermilab:scientific_linux:mtdev-devel, p-cpe:/a:fermilab:scientific_linux:pixman, p-cpe:/a:fermilab:scientific_linux:pixman-devel, p-cpe:/a:fermilab:scientific_linux:xcb-proto, p-cpe:/a:fermilab:scientific_linux:xorg-x11-apps, p-cpe:/a:fermilab:scientific_linux:xorg-x11-apps-debuginfo, p-cpe:/a:fermilab:scientific_linux:xorg-x11-docs, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drivers, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-acecad, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-aiptek, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-apm, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-ast, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-ati, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-ati-firmware, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-cirrus, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-dummy, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-elographics, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-evdev, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-evdev-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-fbdev, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-fpit, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-geode, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-glint, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-hyperpen, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-i128, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-i740, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-intel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-intel-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-keyboard, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-mach64, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-mga, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-modesetting, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-mouse, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-mouse-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-mutouch, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-neomagic, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-nouveau, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-nv, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-openchrome, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-openchrome-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-penmount, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-qxl, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-r128, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-rendition, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-s3virge, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-savage, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-siliconmotion, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-sis, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-sisusb, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-synaptics, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-synaptics-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-tdfx, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-trident, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-v4l, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-vesa, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-vmmouse, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-vmware, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-void, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-voodoo, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-wacom, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-wacom-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-drv-xgi, p-cpe:/a:fermilab:scientific_linux:xorg-x11-proto-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-xdmx, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-xephyr, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-xnest, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-xorg, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-xvfb, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-common, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-source, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-utils, p-cpe:/a:fermilab:scientific_linux:xorg-x11-server-utils-debuginfo, p-cpe:/a:fermilab:scientific_linux:xorg-x11-util-macros, p-cpe:/a:fermilab:scientific_linux:xorg-x11-utils, p-cpe:/a:fermilab:scientific_linux:xorg-x11-utils-debuginfo, p-cpe:/a:fermilab:scientific_linux:xorg-x11-xkb-extras, p-cpe:/a:fermilab:scientific_linux:xorg-x11-xkb-utils, p-cpe:/a:fermilab:scientific_linux:xorg-x11-xkb-utils-devel, p-cpe:/a:fermilab:scientific_linux:xorg-x11-xtrans-devel, x-cpe:/o:fermilab:scientific_linux

必需的 KB 项: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

补丁发布日期: 2013/2/21

漏洞发布日期: 2013/3/8

参考资料信息

CVE: CVE-2011-2504