SuSE 11.2 / 11.3 Security Update : xorg-x11-server (SAT Patch Numbers 8463 / 8464)

medium Nessus Plugin ID 70961

Synopsis

The remote SuSE 11 host is missing one or more security updates.

Description

xorg-x11-server was updated to fix the following security issue :

- Fixed a security issue in which an authenticated X client can cause an X server to use memory after it was freed, potentially leading to crash and/or memory corruption. (CVE-2013-4396, bnc#843652)

A non-security issues was also fixed :

- rfbAuthReenable is accessing rfbClient structure that was in most cases already freed. It actually needs only ScreenPtr, so pass it directly. (bnc#816813)

Solution

Apply SAT patch number 8463 / 8464 as appropriate.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=816813

https://bugzilla.novell.com/show_bug.cgi?id=843652

http://support.novell.com/security/cve/CVE-2013-4396.html

Plugin Details

Severity: Medium

ID: 70961

File Name: suse_11_xorg-x11-Xvnc-131022.nasl

Version: 1.3

Type: local

Agent: unix

Published: 11/19/2013

Updated: 1/19/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:xorg-x11-server-extra, cpe:/o:novell:suse_linux:11, p-cpe:/a:novell:suse_linux:11:xorg-x11-xvnc, p-cpe:/a:novell:suse_linux:11:xorg-x11-server

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 10/22/2013

Reference Information

CVE: CVE-2013-4396