Bug 38250 - libx11: Multiple issues (4.0)
libx11: Multiple issues (4.0)
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.0
Other Linux
: P3 normal (vote)
: UCS 4.0-1-errata
Assigned To: Arvid Requate
Janek Walkenhorst
Depends on:
  Show dependency treegraph
Reported: 2015-04-13 15:47 CEST by Arvid Requate
Modified: 2015-05-07 17:48 CEST (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:
requate: Patch_Available+


Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2015-04-13 15:47:27 CEST
4-byte buffer overflow in MakeBigReq (CVE-2013-7439)

Note: As this is a macro, of course all maintained libraries that use the macro or SetReqLen to create large requests will need to be recompiled: libxrender libxi libxfixes libxrandr libsdl1.2 libxv xserver-xorg-video-vmware cairo (see Debian sec tracker for current list). Probably we can release them independently one after the other but we should check that they don't break at the moment this libx11 update is rolled out.
Comment 1 Arvid Requate univentionstaff 2015-04-15 16:51:52 CEST
The DSA version has been imported and built in errata4.0-1.

Advisory: 2015-04-15-libx11.yaml

All dependent packages have been cherrypicked from UCS-4.0-0 and rebuilt in errata4.0-1:

libxfixes libxrandr libxext libsdl1.2 libxrender libxi libxv cairo wine-gecko-1.4 tightvnc xserver-xorg-video-vmware open-vm-tools texlive-bin libreoffice iceweasel (via Bug 38271).

Corresponding advisories have been commited.
Comment 2 Janek Walkenhorst univentionstaff 2015-05-06 17:13:39 CEST
Installation: OK
Tests: OK
Advisories: OK