Bug 38250

Summary: libx11: Multiple issues (4.0)
Product: UCS Reporter: Arvid Requate <requate>
Component: Security updatesAssignee: Arvid Requate <requate>
Status: CLOSED FIXED QA Contact: Janek Walkenhorst <walkenhorst>
Severity: normal    
Priority: P3 CC: gohmann
Version: UCS 4.0Flags: requate: Patch_Available+
Target Milestone: UCS 4.0-1-errata   
Hardware: Other   
OS: Linux   
What kind of report is it?: --- What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional): Security
Max CVSS v3 score:

Description Arvid Requate univentionstaff 2015-04-13 15:47:27 CEST
4-byte buffer overflow in MakeBigReq (CVE-2013-7439)

Note: As this is a macro, of course all maintained libraries that use the macro or SetReqLen to create large requests will need to be recompiled: libxrender libxi libxfixes libxrandr libsdl1.2 libxv xserver-xorg-video-vmware cairo (see Debian sec tracker for current list). Probably we can release them independently one after the other but we should check that they don't break at the moment this libx11 update is rolled out.
Comment 1 Arvid Requate univentionstaff 2015-04-15 16:51:52 CEST
The DSA version has been imported and built in errata4.0-1.

Advisory: 2015-04-15-libx11.yaml

All dependent packages have been cherrypicked from UCS-4.0-0 and rebuilt in errata4.0-1:

libxfixes libxrandr libxext libsdl1.2 libxrender libxi libxv cairo wine-gecko-1.4 tightvnc xserver-xorg-video-vmware open-vm-tools texlive-bin libreoffice iceweasel (via Bug 38271).

Corresponding advisories have been commited.
Comment 2 Janek Walkenhorst univentionstaff 2015-05-06 17:13:39 CEST
Installation: OK
Tests: OK
Advisories: OK