Re: XFree86-4.3.0 Xft vulnerability patch, round 2

Kelledin <[email protected]>
Newsgroups gmane.linux.lfs.beyond.devel,gmane.linux.lfs.security
Message-ID <[email protected]>
On Sunday 31 August 2003 01:30 pm, Kelledin wrote:
> "blemix" <[email protected]> recently reported a series of
> integer overflow vulnerabilities in XFree86 4.3.0 to the
> [email protected] mailing list.  Primarily these are
> integer overflow errors which in certain configurations could
> lead to the X server executing arbitrary code.

Matthieu Herrb revised his fixes.  Some of the revisions appear 
functionally pertinent to 64-bit platforms, some are just for 
cleanliness.  In any event, here's the revised patch, backported 
again.  It compiles and seems to work.

http://skarpsey.dyndns.org/XFree86-4.3.0-xftfix-2.patch.bz2

(I really wish I had some proof-of-concept code to go on now...)

-- 
Kelledin
"If a server crashes in a server farm and no one pings it, does 
it still cost four figures to fix?"

-- 
http://linuxfromscratch.org/mailman/listinfo/blfs-dev
Unsubscribe: See the above information page
XFree86-4.3.0-xftfix-2.patch.bz2 (application/x-bzip2, 2.8 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.