XFree86 MIT-SHM Shared Memory Access Vulnerability

BID:4396

Info

XFree86 MIT-SHM Shared Memory Access Vulnerability

Bugtraq ID: 4396
Class: Access Validation Error
CVE: CVE-2002-0164
CVE-2002-0164
Remote: No
Local: Yes
Published: Mar 15 2002 12:00AM
Updated: Mar 19 2015 09:17AM
Credit: Vulnerability discovery credited to Roberto Zunino.
Vulnerable: XFree86 X11R6 4.2.1
+ Immunix Immunix OS 7.3
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ Mandriva Linux Mandrake 9.0
+ RedHat Linux 7.3
+ Slackware Linux 8.1
XFree86 X11R6 4.2 .0
+ Conectiva Linux Enterprise Edition 1.0
+ S.u.S.E. Linux 8.0 i386
+ S.u.S.E. Linux 8.0
+ Turbolinux Turbolinux Server 8.0
+ Turbolinux Turbolinux Workstation 8.0
XFree86 X11R6 4.1 .0
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Red Hat Enterprise Linux AS 2.1
+ RedHat Advanced Workstation for the Itanium Processor 2.1
+ RedHat Enterprise Linux ES 2.1
+ RedHat Enterprise Linux WS 2.1
+ RedHat Linux 7.2 i386
+ RedHat Linux 7.1 i386
+ Turbolinux Turbolinux Server 7.0
+ Turbolinux Turbolinux Workstation 7.0
XFree86 X11R6 4.1 -11
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Workstation 3.1.1
XFree86 X11R6 4.0.3
+ RedHat Linux 7.1
XFree86 X11R6 4.0.2 -11
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1
XFree86 X11R6 4.0.1
+ RedHat Linux 7.0
XFree86 X11R6 4.0
Sun Linux 5.0.6
SGI IRIX 6.5.17 m
SGI IRIX 6.5.17 f
SGI IRIX 6.5.16 m
SGI IRIX 6.5.16 f
SGI IRIX 6.5.15 m
SGI IRIX 6.5.15 f
SGI IRIX 6.5.14 m
SGI IRIX 6.5.14 f
SGI IRIX 6.5.13 m
SGI IRIX 6.5.13 f
SGI IRIX 6.5.12
SGI IRIX 6.5.11
SGI IRIX 6.5.10
SGI IRIX 6.5.9
SGI IRIX 6.5.8
SGI IRIX 6.5.7
SGI IRIX 6.5.6
SGI IRIX 6.5.5
SGI IRIX 6.5.4
SGI IRIX 6.5.3
SGI IRIX 6.5.2
SGI IRIX 6.5.1
SGI IRIX 6.5
SCO Open Server 5.0.7
SCO Open Server 5.0.6
SCO Open Server 5.0.5
SCO Open Server 5.0.4
SCO Open Server 5.0.3
SCO Open Server 5.0.2
SCO Open Server 5.0.1
SCO Open Server 5.0
RedHat XFree86-Xvfb-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-Xnest-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-xfs-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-xdm-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-xauth-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-twm-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-truetype-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-tools-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-Mesa-libGLU-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-Mesa-libGL-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-libs-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-ISO8859-9-75dpi-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-ISO8859-9-100dpi-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-ISO8859-2-75dpi-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-ISO8859-2-100dpi-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-ISO8859-15-75dpi-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-ISO8859-15-100dpi-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-font-utils-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-doc-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-devel-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-cyrillic-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-base-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-75dpi-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat XFree86-100dpi-fonts-4.2.0-72.i386.rpm
+ RedHat Linux 8.0 i386
RedHat Linux 8.0 i386
Gentoo Linux 1.4 _rc1
Gentoo Linux 1.2
Caldera UnixWare 7.1.1
Caldera OpenUnix 8.0
Not Vulnerable: XFree86 X11R6 4.2.1 Errata
XFree86 X11R6 4.1 -12
- Caldera OpenLinux Server 3.1.1
- Caldera OpenLinux Server 3.1.1
- Caldera OpenLinux Workstation 3.1.1
SGI IRIX 6.5.18

Discussion

XFree86 MIT-SHM Shared Memory Access Vulnerability

The MIT-SHM extension for XFree86 provides System V shared memory to X processes. Various operating systems shipped with XFree86 versions prior to 4.1 have support for this shared memory scheme enabled.

This configuration is vulnerable to a problem that allows local X users to gain read and write access to any shared memory segment on the system. This could allow interference with other users and possibly elevation of privileges, depending on the context.

Other configurations of XFree86 may be vulnerable to this problem, depending on whether or not System V shared memory and MIT-SHM has been enabled.

Exploit / POC

XFree86 MIT-SHM Shared Memory Access Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

XFree86 MIT-SHM Shared Memory Access Vulnerability

Solution:
Red Hat has released an advisory (RHSA-2003:064-01) to address this issue. Details on obtaining and applying fixes are contained in the referenced advisory.

Red Hat has released a revised advisory (RHSA-2003:067-02) to address this issue. Fixes from the previous advisory (RHSA-2003:067-01) are functional but contain debugging info. The revised advisory includes new fixes that do not contain debugging info. Details on obtaining and applying fixes are contained in the revised advisory.

FreeBSD has released upgrades. Users are advised to upgrade their Ports
collection and reinstall the affected port.

SGI has released an advisory. SGI strongly advises users to either download and install the appropriate patches or to upgrade to IRIX 6.5.18 when it is available. Further details are available in the referenced advisory.

Conectiva has released an advisory (CLA-2002:533) containing fixes for Conectiva Linux 6.0 and 7.0. Further details about obtaining fixes are available in the attached advisory.

Gentoo Linux has released an advisory. Users of x11-base/xfree-4.2.0-r12 and earlier are urged to update their systems by issuing the following commands:

emerge rsync
emerge xfree
emerge clean

Sun has released updates correcting this issue.

Debian has released an advisory (DSA 380-1) with fixes to address this issue. Please see the referenced advisory for more information.

SCO has released advisory CSSA-2003-SCO.26 to address this issue.

Upgrades are available:


RedHat XFree86-ISO8859-9-75dpi-fonts-4.2.0-72.i386.rpm

RedHat XFree86-Xnest-4.2.0-72.i386.rpm

RedHat XFree86-libs-4.2.0-72.i386.rpm

RedHat XFree86-Mesa-libGLU-4.2.0-72.i386.rpm

RedHat XFree86-100dpi-fonts-4.2.0-72.i386.rpm

RedHat XFree86-ISO8859-2-100dpi-fonts-4.2.0-72.i386.rpm

RedHat XFree86-doc-4.2.0-72.i386.rpm

RedHat XFree86-font-utils-4.2.0-72.i386.rpm

RedHat XFree86-ISO8859-2-75dpi-fonts-4.2.0-72.i386.rpm

RedHat XFree86-Xvfb-4.2.0-72.i386.rpm

RedHat XFree86-ISO8859-15-100dpi-fonts-4.2.0-72.i386.rpm

RedHat XFree86-xdm-4.2.0-72.i386.rpm

RedHat XFree86-base-fonts-4.2.0-72.i386.rpm

RedHat XFree86-truetype-fonts-4.2.0-72.i386.rpm

RedHat XFree86-4.2.0-72.i386.rpm

RedHat XFree86-xfs-4.2.0-72.i386.rpm

RedHat XFree86-cyrillic-fonts-4.2.0-72.i386.rpm

RedHat XFree86-ISO8859-15-75dpi-fonts-4.2.0-72.i386.rpm

RedHat XFree86-tools-4.2.0-72.i386.rpm

RedHat XFree86-devel-4.2.0-72.i386.rpm

RedHat XFree86-75dpi-fonts-4.2.0-72.i386.rpm

RedHat XFree86-ISO8859-9-100dpi-fonts-4.2.0-72.i386.rpm

RedHat XFree86-xauth-4.2.0-72.i386.rpm

RedHat XFree86-Mesa-libGL-4.2.0-72.i386.rpm

XFree86 X11R6 4.1 .0

XFree86 X11R6 4.1 -11

XFree86 X11R6 4.2 .0

SCO Open Server 5.0

SCO Open Server 5.0.1

SCO Open Server 5.0.2

SCO Open Server 5.0.3

SCO Open Server 5.0.4

SCO Open Server 5.0.5

SCO Open Server 5.0.6

Sun Linux 5.0.6

SCO Open Server 5.0.7

SGI IRIX 6.5.13 f

SGI IRIX 6.5.13 m

SGI IRIX 6.5.14 f

SGI IRIX 6.5.14 m

SGI IRIX 6.5.15 m

SGI IRIX 6.5.15 f

SGI IRIX 6.5.16 f

SGI IRIX 6.5.16 m

SGI IRIX 6.5.17 m

SGI IRIX 6.5.17 f

Caldera UnixWare 7.1.1

Caldera OpenUnix 8.0

References

XFree86 MIT-SHM Shared Memory Access Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report