iDefense reported several integer overflow flaws in the XFree86 server source. These flaws may allow a local user to leverage these flaws to become root.
These flaws also affect RHEL2.1
Created attachment 143094 [details] Upstream patch
Built as XFree86-4.3.0-114.EL for RHEL3. RHEL 2.1 is waiting for beehive to wake up.
XFree86-4.1.0-78.EL for RHEL 2.1
correction, -115 for RHEL3.
These issues are public: http://lists.freedesktop.org/archives/xorg-announce/2007-January/000235.html
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2007-0002.html