Re: XFree86-4.3.0 Xft vulnerability patch, round 3
Kelledin <[email protected]>
| Newsgroups | gmane.linux.lfs.beyond.devel,gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday 02 September 2003 07:37 pm, Kelledin wrote: > On Sunday 31 August 2003 01:30 pm, Kelledin wrote: > > "blemix" <[email protected]> recently reported a series of > > integer overflow vulnerabilities in XFree86 4.3.0 to the > > [email protected] mailing list. Primarily these are > > integer overflow errors which in certain configurations > > could lead to the X server executing arbitrary code. > > Matthieu Herrb revised his fixes. Some of the revisions > appear functionally pertinent to 64-bit platforms, some are > just for cleanliness. In any event, here's the revised patch, > backported again. It compiles and seems to work. Well...irony of ironies, somebody found some integer overflows in the integer overflow checks. Ain't life grand? ;-) http://skarpsey.dyndns.org/XFree86-4.3.0-xftfix-3.patch.bz2 -- Kelledin "If a server crashes in a server farm and no one pings it, does it still cost four figures to fix?" -- http://linuxfromscratch.org/mailman/listinfo/blfs-dev FAQ: http://www.linuxfromscratch.org/blfs/faq.html Unsubscribe: See the above information page
XFree86-4.3.0-xftfix-3.patch.bz2
(application/x-bzip2, 2.7 KB) - not displayed