Please read the http://frugalware.org/docs/bugs page if you are new to bugreporting!
FS#2709 - [SEC] xorg-server + libxfont
Attached to Project:
Frugalware
Opened by crazy (bugs) - Saturday, 19 January 2008, 09:46 GMT+2
Last edited by Miklos Vajna (vmiklos) - Friday, 14 March 2008, 23:03 GMT+2
Opened by crazy (bugs) - Saturday, 19 January 2008, 09:46 GMT+2
Last edited by Miklos Vajna (vmiklos) - Friday, 14 March 2008, 23:03 GMT+2
|
Details http://lists.freedesktop.org/archives/xorg/2008-January/031918.html
WARNING! Please no one pushes this to stable yet : * CVE-2007-6429 - MIT-SHM and EVI extensions integer overflows this one breaks more as it fixes , see : https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/183969 http://secunia.com/advisories/28532/ |
This task depends upon
Closed by Miklos Vajna (vmiklos)
Friday, 14 March 2008, 23:03 GMT+2
Reason for closing: Fixed
Additional comments about closing: Kalgan is out
Friday, 14 March 2008, 23:03 GMT+2
Reason for closing: Fixed
Additional comments about closing: Kalgan is out
http://gitweb.freedesktop.org/?p=xorg/xserver.git;a=commitdiff;h=e9fa7c1c88a8130a48f772c92b186b8b777986b5;hp=23f3f0e27dc90b7b3a375f2a5dd094e6f53552b5
I will test in xorg73 first.
http://frugalware.org/pipermail/frugalware-git/2008-January/007387.html
http://frugalware.org/pipermail/frugalware-git/2008-January/007385.html
http://frugalware.org/pipermail/frugalware-git/2008-January/007389.html
http://cgit.freedesktop.org/xorg/xserver/commit/?id=be6c17fcf9efebc0bbcc3d9a25f8c5a2450c2161
we should wait some more days for stable with that.
I'll fix for current later on
libxfont first :
ftp://ftp.freedesktop.org/pub/xorg/X11R7.2/patches/xorg-libXfont-1.2.7-pcf-parser.diff
xorg-server:
ftp://ftp.freedesktop.org/pub/xorg/X11R7.2/patches/xorg-xserver-1.2-multiple-overflows-v2.diff + http://gitweb.freedesktop.org/?p=xorg/xserver.git;a=commitdiff;h=be6c17fcf9efebc0bbcc3d9a25f8c5a2450c2161;hp=94a21d757ce58254accbd5dd3a86810aadeec9f0
I also suggest putting this fix for CVE-2007-3069 as well , was forgotten :
http://lists.freedesktop.org/archives/xorg/2008-January/032129.html
In meantime xorg-server for current compiles , I'll update the status in a bit.
http://frugalware.org/pipermail/frugalware-git/2008-January/007551.html