Re: XFree86-4.3.0 Xft vulnerability patch, round 3

Kelledin <[email protected]>
Newsgroups gmane.linux.lfs.beyond.devel,gmane.linux.lfs.security
Message-ID <[email protected]>
On Tuesday 02 September 2003 07:37 pm, Kelledin wrote:
> On Sunday 31 August 2003 01:30 pm, Kelledin wrote:
> > "blemix" <[email protected]> recently reported a series of
> > integer overflow vulnerabilities in XFree86 4.3.0 to the
> > [email protected] mailing list.  Primarily these are
> > integer overflow errors which in certain configurations
> > could lead to the X server executing arbitrary code.
>
> Matthieu Herrb revised his fixes.  Some of the revisions
> appear functionally pertinent to 64-bit platforms, some are
> just for cleanliness.  In any event, here's the revised patch,
> backported again.  It compiles and seems to work.

Well...irony of ironies, somebody found some integer overflows in 
the integer overflow checks.  Ain't life grand? ;-)

http://skarpsey.dyndns.org/XFree86-4.3.0-xftfix-3.patch.bz2

-- 
Kelledin
"If a server crashes in a server farm and no one pings it, does 
it still cost four figures to fix?"

-- 
http://linuxfromscratch.org/mailman/listinfo/blfs-dev
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page
XFree86-4.3.0-xftfix-3.patch.bz2 (application/x-bzip2, 2.7 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.