Bug 10877 - RedHat 6.x X Font Server DoS Vulnerability
Summary: RedHat 6.x X Font Server DoS Vulnerability
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: XFree86 (Show other bugs)
(Show other bugs)
Version: 6.2
Hardware: All Linux
Target Milestone: ---
Assignee: Mike A. Harris
QA Contact:
URL: http://www.securityfocus.com/vdb/bott...
Keywords: Security
: 10897 10951 (view as bug list)
Depends On:
TreeView+ depends on / blocked
Reported: 2000-04-17 18:38 UTC by Matthew Miller
Modified: 2008-05-01 15:37 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2001-04-24 16:27:36 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2001:071 high SHIPPED_LIVE : New updated XFree86 packages available 2001-05-24 04:00:00 UTC

Description Matthew Miller 2000-04-17 18:38:15 UTC
See: http://www.securityfocus.com/vdb/bottom.html?vid=1111

From the discussion there:

A denial of service exists in the X11 font server shipped with RedHat Linux
6.x. Due to improper input validation, it is possible for any user to crash
the X fontserver. This will prevent the X server from functioning properly.

(There is also an exploit:
http://www.securityfocus.com/data/vulnerabilities/exploits/kill-xfs.c )

Comment 1 Bill Nottingham 2000-04-18 19:27:59 UTC
*** Bug 10897 has been marked as a duplicate of this bug. ***

Comment 2 Matthew Miller 2000-05-24 17:39:59 UTC
Any word on this? Not only would it be nice to have these things fixed, it looks
bad for Linux in general when it takes a long time. (See, for instance

(I'm sorry that I don't have the programming skills myself to give you a patch.)

Comment 3 Bernhard Rosenkraenzer 2000-12-20 12:50:47 UTC
*** Bug 10951 has been marked as a duplicate of this bug. ***

Comment 4 Mike A. Harris 2001-05-25 14:45:54 UTC
Fixed in our currently pending errata soon to be released.

Note You need to log in before you can comment on or make changes to this bug.