Bug 10877

Summary: RedHat 6.x X Font Server DoS Vulnerability
Product: [Retired] Red Hat Linux Reporter: Matthew Miller <mattdm>
Component: XFree86Assignee: Mike A. Harris <mharris>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: high    
Version: 6.2CC: yiango
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://www.securityfocus.com/vdb/bottom.html?vid=1111
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2001-04-24 16:27:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Matthew Miller 2000-04-17 18:38:15 UTC
See: http://www.securityfocus.com/vdb/bottom.html?vid=1111

From the discussion there:

A denial of service exists in the X11 font server shipped with RedHat Linux
6.x. Due to improper input validation, it is possible for any user to crash
the X fontserver. This will prevent the X server from functioning properly.

(There is also an exploit:
http://www.securityfocus.com/data/vulnerabilities/exploits/kill-xfs.c )

Comment 1 Bill Nottingham 2000-04-18 19:27:59 UTC
*** Bug 10897 has been marked as a duplicate of this bug. ***

Comment 2 Matthew Miller 2000-05-24 17:39:59 UTC
Any word on this? Not only would it be nice to have these things fixed, it looks
bad for Linux in general when it takes a long time. (See, for instance
http://www.securityfocus.com/frames/?content=/vdb/stats.html)

(I'm sorry that I don't have the programming skills myself to give you a patch.)

Comment 3 Bernhard Rosenkraenzer 2000-12-20 12:50:47 UTC
*** Bug 10951 has been marked as a duplicate of this bug. ***

Comment 4 Mike A. Harris 2001-05-25 14:45:54 UTC
Fixed in our currently pending errata soon to be released.