libXfont (SSA:2017-333-02)
[slackware-security] libXfont (SSA:2017-333-02)
Date: Wed, 29 Nov 2017 00:19:27 -0800 (PST)

[slackware-security] libXfont (SSA:2017-333-02)

New libXfont packages are available for Slackware 13.0, 13.1, 13.37, 14.0,
14.1, and 14.2 to fix a security issue.

Here are the details from the Slackware 14.2 ChangeLog:
patches/packages/libXfont-1.5.1-i486-2_slack14.2.txz: Rebuilt.
Open files with O_NOFOLLOW. (CVE-2017-16611)
A non-privileged X client can instruct X server running under root
to open any file by creating own directory with "fonts.dir",
"fonts.alias" or any font file being a symbolic link to any other
file in the system. X server will then open it. This can be issue
with special files such as /dev/watchdog (which could then reboot
the system).
For more information, see:
(* Security fix *)

Where to find the new packages:

Installation instructions:

Upgrade the package as root:
# upgradepkg libXfont-1.5.1-i486-2_slack14.2.txz


Slackware Linux Security Team

