XFree86-4.3.0 Xft vulnerability patch
Kelledin <[email protected]>
| Newsgroups | gmane.linux.lfs.beyond.devel,gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
"blemix" <[email protected]> recently reported a series of integer overflow vulnerabilities in XFree86 4.3.0 to the [email protected] mailing list. Primarily these are integer overflow errors which in certain configurations could lead to the X server executing arbitrary code. http://www.securityfocus.com/archive/1/335592/2003-08-28/2003-09-03/0 The bugs are (at least partially) fixed in XFree86-CVS. A couple of comments in the code suggest that they're not completely fixed--I'm watching the XFree86 CVS commits, so I'll probably know if further fixes come down the pipe. In the meantime I took the liberty of backporting the incremental diffs from CVS and creating a patch that applies to both XFree86 4.3.0 and 4.3.0.1. So far all I can say is, "it compiles, and it _seems_ to work." The patch can be found at http://skarpsey.dyndns.org/XFree86-4.3.0-xftfix-1.patch.bz2 (or attached to this message). -- Kelledin "If a server crashes in a server farm and no one pings it, does it still cost four figures to fix?" -- http://linuxfromscratch.org/mailman/listinfo/blfs-dev Unsubscribe: See the above information page
XFree86-4.3.0-xftfix-1.patch.bz2
(application/x-bzip2, 2.8 KB) - not displayed