XFree86-4.3.0 Xft vulnerability patch

Kelledin <[email protected]>
Newsgroups gmane.linux.lfs.beyond.devel,gmane.linux.lfs.security
Message-ID <[email protected]>
"blemix" <[email protected]> recently reported a series of integer 
overflow vulnerabilities in XFree86 4.3.0 to the 
[email protected] mailing list.  Primarily these are 
integer overflow errors which in certain configurations could 
lead to the X server executing arbitrary code.

http://www.securityfocus.com/archive/1/335592/2003-08-28/2003-09-03/0

The bugs are (at least partially) fixed in XFree86-CVS.  A couple 
of comments in the code suggest that they're not completely 
fixed--I'm watching the XFree86 CVS commits, so I'll probably 
know if further fixes come down the pipe.  In the meantime I 
took the liberty of backporting the incremental diffs from CVS 
and creating a patch that applies to both XFree86 4.3.0 and 
4.3.0.1.  So far all I can say is, "it compiles, and it _seems_ 
to work."

The patch can be found at 
http://skarpsey.dyndns.org/XFree86-4.3.0-xftfix-1.patch.bz2 (or 
attached to this message).

-- 
Kelledin
"If a server crashes in a server farm and no one pings it, does 
it still cost four figures to fix?"

-- 
http://linuxfromscratch.org/mailman/listinfo/blfs-dev
Unsubscribe: See the above information page
XFree86-4.3.0-xftfix-1.patch.bz2 (application/x-bzip2, 2.8 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.