[rock-user] [Security Announcement] xorg (RLSA-20060322-01)

"Daniel Jahre" <[email protected]> Wed, 22 Mar 2006 17:19:49 +0100
Newsgroups gmane.linux.distributions.rock.user
Message-ID <[email protected]>
This is a ROCK Linux Security Announcement.

Package: xorg
Announcement ID: RLSA-20060322-01
Date: 2006-03-22
Affected Distributions: Crystal, LiveCD
Affected Releases: none
Cross References: CVE-2006-0745

Content of this advisory:
Content of this advisory:
1) Problem Description
2) Solution or Work-Around
3) Special instructions and notes
4) Updateing your source tree
5) Source package update
6) Binary package update

--------------------------------------------------------------------------------

1) Problem Description
There is a flaw in the server that allows local users to execute
arbitrary code with root privileges, or cause a denial of service by
overwriting files on the system, again with root privileges.
See http://www.securityfocus.com/archive/1/428183/30/0/threaded
for details.

2) Solution or Workaround
There is no known Work-Around. Since there is no new release of the xorg
package we added a patch to the package repository. Please rebuild that
package.

3) Special instruction and notes
This applies only to distributions which include version 6.9 of X.Org.
Older versions like X.Org 6.8.x are not affected.

4) Updateing your source tree
If you are using a subversion checkout of trunk, run:
   svn up

If you are using submaster run,
  sm sync
to merge the update from trunk into your tree

5) Source package update
As a user of an affected distribution you can update this package by
rebuilding it on your machine
run
   rocket updsrc
to update your local sources and
   rocket emerge xorg
to install the updated package

6) Binary package update
there are no new binary packages available for this package yet.