Re: XFree86-4.3.0 Xft vulnerability patch, round 2
Kelledin <[email protected]>
| Newsgroups | gmane.linux.lfs.beyond.devel,gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Sunday 31 August 2003 01:30 pm, Kelledin wrote: > "blemix" <[email protected]> recently reported a series of > integer overflow vulnerabilities in XFree86 4.3.0 to the > [email protected] mailing list. Primarily these are > integer overflow errors which in certain configurations could > lead to the X server executing arbitrary code. Matthieu Herrb revised his fixes. Some of the revisions appear functionally pertinent to 64-bit platforms, some are just for cleanliness. In any event, here's the revised patch, backported again. It compiles and seems to work. http://skarpsey.dyndns.org/XFree86-4.3.0-xftfix-2.patch.bz2 (I really wish I had some proof-of-concept code to go on now...) -- Kelledin "If a server crashes in a server farm and no one pings it, does it still cost four figures to fix?" -- http://linuxfromscratch.org/mailman/listinfo/blfs-dev Unsubscribe: See the above information page
XFree86-4.3.0-xftfix-2.patch.bz2
(application/x-bzip2, 2.8 KB) - not displayed