New branch 'debian-wheezy' available with the following commits: commit 9dccb86d48d47d6735fb40c2c56858f7a299b0a3 Author: Julien Cristau <jcris...@debian.org> Date: Tue May 14 00:41:37 2013 +0200
Upload to wheezy-security commit e9cba4fa285f4eb93cea8a8ea1d8d98bce205fb7 Author: Alan Coopersmith <alan.coopersm...@oracle.com> Date: Fri Apr 12 21:17:28 2013 -0700 signedness bug & integer overflow in _XcursorFileHeaderCreate() [CVE-2013-2003] When parsing cursor files, a user defined (e.g. through environment variables) cursor file is opened and parsed. The header is read in _XcursorReadFileHeader(), which reads an unsigned int for the number of toc structures in the header, but it was being passed to _XcursorFileHeaderCreate() as a signed int to allocate those structures. If the number was negative, it would pass the bounds check and could overflow the calculation for how much memory to allocate to store the data being read, leading to overflowing the buffer with the data read from the user controlled file. Reported-by: Ilja Van Sprundel <ivansprun...@ioactive.com> Signed-off-by: Alan Coopersmith <alan.coopersm...@oracle.com> Signed-off-by: Julien Cristau <jcris...@debian.org> -- To UNSUBSCRIBE, email to debian-x-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/e1ufaj5-0002dx...@vasks.debian.org