Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Thread Tools Display Modes
  #1   (View Single Post)  
Old 25th May 2013
shep shep is offline
Rc.conf Instructor
Join Date: May 2008
Location: Dry and Dusty
Posts: 1,111
Default Protocol handling issues in X Window System client libraries

Ilja van Sprundel, a security researcher with IOActive, has discovered
a large number of issues in the way various X client libraries handle
the responses they receive from servers, and has worked with X.Org's
security team to analyze, confirm, and fix these issues.

Most of these issues stem from the client libraries trusting the server
to send correct protocol data, and not verifying that the values will
not overflow or cause other damage. Most of the time X clients & servers
are run by the same user, with the server more privileged from the clients,
so this is not a problem, but there are scenarios in which a privileged
client can be connected to an unprivileged server, for instance, connecting
a setuid X client (such as a screen lock program) to a virtual X server
(such as Xvfb or Xephyr) which the user has modified to return invalid
data, potentially allowing the user to escalate their privileges.

The CVE's are almost TNTC (Too numerous to count) and I would be very impressed if OpenBSD's xorg implementation escapes unscathed.
Reply With Quote
  #2   (View Single Post)  
Old 1st June 2013
shep shep is offline
Rc.conf Instructor
Join Date: May 2008
Location: Dry and Dusty
Posts: 1,111

Some Follow Up on the Xorg vulnerabilities
Merge upstream fixes for several X(7) library vulnerabilities (integer overflows/buffer overflows/memory corruption).
From OpenBSD current changelog.

Would the developers consider xorg as part of the "Default Install" making it a candidate for a patch? If it is patched, given the multiple vulnerabilities, it could either be a new install set or lots of individual patches.
Reply With Quote

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenBSD's version of the X Window System Zyos OpenBSD Security 4 7th November 2011 12:04 AM
Snort 2.9.1 improves protocol handling J65nko News 0 30th August 2011 12:26 AM
Immense delayed write to file system (ZFS and UFS2), performance issues J65nko FreeBSD General 12 15th September 2010 11:46 PM
OBSD client hangs mounting NFS; Linux client doesn't amorphousone OpenBSD General 7 26th August 2010 05:21 AM
I386 ELF32 binary on AMD64 system can't find shared libraries Gemini FreeBSD General 0 9th December 2008 06:49 AM

All times are GMT. The time now is 04:57 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2018, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick