Important: libXfont (SL5, SL6)

Synopsis: Important: libXfont security update
Issue Date: 2011-08-11
CVE Numbers: CVE-2011-2895

The libXfont packages provide the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

A buffer overflow flaw was found in the way the libXfont library, used by
the X.Org server, handled malformed font files compressed using UNIX
compress. A malicious, local user could exploit this issue to potentially
execute arbitrary code with the privileges of the X.Org server.
(CVE-2011-2895)

Users of libXfont should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for the update to take effect.

SL5
x86_64
libXfont-1.2.2-1.0.4.el5_7.i386.rpm
libXfont-1.2.2-1.0.4.el5_7.x86_64.rpm
libXfont-devel-1.2.2-1.0.4.el5_7.i386.rpm
libXfont-devel-1.2.2-1.0.4.el5_7.x86_64.rpm
i386
libXfont-1.2.2-1.0.4.el5_7.i386.rpm
libXfont-devel-1.2.2-1.0.4.el5_7.i386.rpm
SL6
x86_64
libXfont-1.4.1-2.el6_1.i686.rpm
libXfont-1.4.1-2.el6_1.x86_64.rpm
libXfont-devel-1.4.1-2.el6_1.i686.rpm
libXfont-devel-1.4.1-2.el6_1.x86_64.rpm
i386
libXfont-1.4.1-2.el6_1.i686.rpm
libXfont-devel-1.4.1-2.el6_1.i686.rpm

– Scientific Linux Development Team