OBSOLETE Patch-ID# 113924-05
Download this patch from My Oracle Support
Your use of the firmware, software and any other materials contained
in this update is subject to My Oracle Support Terms of Use, which
may be viewed at My Oracle Support.
|
For further information on patching best practices and resources, please
see the following links:
|
Copyright (c) 2012, Oracle and/or its affiliates. All rights reserved.
|
Keywords: security font server
Synopsis: Obsoleted by: 113924-06 X11 6.6.1_x86: security font server patch
Date: Feb/13/2008
Install Requirements: Reboot after installing this patch to activate the changes delivered. An alternative may be specified in the Special Install Instructions.
Solaris Release: 9_x86
SunOS Release: 5.9_x86
Unbundled Product: X11
Unbundled Release: 6.6.1_x86
Xref: This patch available for SPARC as 113923
Topic:
Relevant Architectures: i386
Bugs fixed with this patch:
Changes incorporated in this version: 6618748
Patches accumulated and obsoleted by this patch:
Patches which conflict with this patch:
Patches required with this patch:
Obsoleted by:
Files included with this patch:
/usr/openwin/bin/xfs
Problem Description:
6618748 xfs patches for S9 and S10 need rebootafter patch property
(from 113924-04)
6601751 [X.Org Bug 12298] *xfs* Integer overflows in build_range()
6601756 [X.Org Bug 12299] *xfs* swap_char2b() Heap Overflow Vulnerability
(from 113924-03)
4915967 integer overflows in X font server
(from 113924-02)
4764193 (rework) CERT Advisory CA-2002-34: xfs crashes on bad request
(from 113924-01)
4764193 xfs crashes on bad request
Patch Installation Instructions:
--------------------------------
Refer to the man pages for instructions on using 'patchadd' and 'patchrm'
scripts provided with Solaris. Any other special or non-generic
installation instructions should be described below as special
instructions. The following example installs a patch to a standalone
machine:
example# patchadd /var/spool/patch/104945-02
The following example removes a patch from a standalone system:
example# patchrm 104945-02
For additional examples please see the appropriate man pages.
Special Install Instructions:
-----------------------------
For the changes in this patch to become effective, a reboot may be performed, or
alternatively, the X Window System font server process, xfs, must be killed if
it is already running.
The X font server, is normally started automatically from inetd on Solaris when
a request for a font service is received. Xsun clients using the font server
will detect the font server shutdown and reconnect automatically to a new
instance of the font server. Unfortunately, some other font clients, such as
some versions of Xvnc, will not reconnect automatically and will need to be
stopped before killing the font server and restarted again after the font server
is restarted. (If xfs is still being run from inetd, inetd will automatically
restart on the first connection attempt).
To kill the font server, as root, run the command:
pkill -x xfs
README -- Last modified date: Friday, November 9, 2012