Bug 31485 - libxres: Multiple issues (3.1)
libxres: Multiple issues (3.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 3.0
Other Linux
: P4 normal (vote)
: UCS 3.2
Assigned To: Moritz Muehlenhoff
Janek Walkenhorst
: interim-3
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-05-24 11:42 CEST by Moritz Muehlenhoff
Modified: 2013-11-19 06:41 CET (History)
0 users

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Moritz Muehlenhoff univentionstaff 2013-05-24 11:42:54 CEST
+++ This bug was initially created as a clone of Bug #31484 +++

CVE-2013-1988

Ilja van Sprundel of IOActive discovered several security issues in
multiple components of the X.org graphics stack and the related
libraries: Various integer overflows, sign handling errors in integer
conversions, buffer overflows, memory corruption and missing input
sanitising may lead to privilege escalation or denial of service.

The package is only unmaintained in UCS 2.4
Comment 1 Moritz Muehlenhoff univentionstaff 2013-07-26 14:14:13 CEST
Fixed in 3.2 through the import of Debian 6.0.8.

The QA should ideally be made by the same person as for Bug 31956.
Comment 2 Janek Walkenhorst univentionstaff 2013-10-21 13:19:10 CEST
(In reply to Moritz Muehlenhoff from comment #1)
> Fixed in 3.2 through the import of Debian 6.0.8.
Correct
Comment 3 Stefan Gohmann univentionstaff 2013-11-19 06:41:43 CET
UCS 3.2 has been released:
 http://docs.univention.de/release-notes-3.2-en.html
 http://docs.univention.de/release-notes-3.2-de.html

If this error occurs again, please use "Clone This Bug".