Hello community,
here is the log from the commit of package patchinfo.1755 for
openSUSE:12.2:Update checked in at 2013-06-19 11:58:44
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:12.2:Update/patchinfo.1755 (Old)
and /work/SRC/openSUSE:12.2:Update/.patchinfo.1755.new (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "patchinfo.1755"
Changes:
--------
New Changes file:
NO CHANGES FILE!!!
New:
----
_patchinfo
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ _patchinfo ++++++
<patchinfo>
<issue id="815451" tracker="bnc">VUL-0: xorg: upcoming fixes for xlib</issue>
<issue id="821664" tracker="bnc">VUL-0: xorg-x11-libX11: X.Org Security
Advisory: May 23, 2013</issue>
<issue id="CVE-2013-1997" tracker="cve" />
<issue id="CVE-2013-1981" tracker="cve" />
<issue id="CVE-2013-2004" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>sndirsch</packager>
<description>This update of libX11 fixes several security issues.
- U_0001-integer-overflow-in-_XQueryFont-on-32-bit-platforms-.patch,
U_0002-integer-overflow-in-_XF86BigfontQueryFont-CVE-2013-1.patch,
U_0003-integer-overflow-in-XListFontsWithInfo-CVE-2013-1981.patch,
U_0004-integer-overflow-in-XGetMotionEvents-CVE-2013-1981-4.patch,
U_0005-integer-overflow-in-XListHosts-CVE-2013-1981-5-13.patch,
U_0006-Integer-overflows-in-stringSectionSize-cause-buffer-.patch,
U_0007-integer-overflow-in-ReadInFile-in-Xrm.c-CVE-2013-198.patch,
U_0008-integer-truncation-in-_XimParseStringFile-CVE-2013-1.patch,
U_0009-integer-overflows-in-TransFileName-CVE-2013-1981-9-1.patch,
U_0010-integer-overflow-in-XGetWindowProperty-CVE-2013-1981.patch,
U_0011-integer-overflow-in-XGetImage-CVE-2013-1981-11-13.patch,
U_0012-integer-overflow-in-XGetPointerMapping-XGetKeyboardM.patch,
U_0013-integer-overflow-in-XGetModifierMapping-CVE-2013-198.patch
* integer overflow in various functions, integer truncation in
_XimParseStringFile() [CVE-2013-1981] (bnc#821664, bnc#815451)
- U_0001-unvalidated-lengths-in-XAllocColorCells-CVE-2013-199.patch,
U_0002-unvalidated-index-in-_XkbReadGetDeviceInfoReply-CVE-.patch,
U_0003-unvalidated-indexes-in-_XkbReadGeomShapes-CVE-2013-1.patch,
U_0004-unvalidated-indexes-in-_XkbReadGetGeometryReply-CVE-.patch,
U_0005-unvalidated-index-in-_XkbReadKeySyms-CVE-2013-1997-5.patch,
U_0006-unvalidated-index-in-_XkbReadKeyActions-CVE-2013-199.patch,
U_0007-unvalidated-index-in-_XkbReadKeyBehaviors-CVE-2013-1.patch,
U_0008-unvalidated-index-in-_XkbReadModifierMap-CVE-2013-19.patch,
U_0009-unvalidated-index-in-_XkbReadExplicitComponents-CVE-.patch,
U_0010-unvalidated-index-in-_XkbReadVirtualModMap-CVE-2013-.patch,
U_0011-unvalidated-index-length-in-_XkbReadGetNamesReply-CV.patch,
U_0012-unvalidated-length-in-_XimXGetReadData-CVE-2013-1997.patch,
U_0013-Avoid-overflows-in-XListFonts-CVE-2013-1997-13-15.patch,
U_0014-Avoid-overflows-in-XGetFontPath-CVE-2013-1997-14-15.patch,
U_0015-Avoid-overflows-in-XListExtensions-CVE-2013-1997-15-.patch
* unvalidated index/length in various functions; Avoid overflows
in XListFonts(), XGetFontPath(), XListExtensions() [CVE-2013-1997]
(bnc##821664, bnc#815451)
- U_0001-Unbounded-recursion-in-GetDatabase-when-parsing-incl.patch,
U_0002-Unbounded-recursion-in-_XimParseStringFile-when-pars.patch
* Unbounded recursion in GetDatabase(), _XimParseStringFile when
parsing include files [CVE-2013-2004] (bnc##821664, bnc#815451)
</description>
<summary>update for libX11</summary>
</patchinfo>
--
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]