Univention Bugzilla – Bug 38250
libx11: Multiple issues (4.0)
Last modified: 2015-05-07 17:48:10 CEST
4-byte buffer overflow in MakeBigReq (CVE-2013-7439) Note: As this is a macro, of course all maintained libraries that use the macro or SetReqLen to create large requests will need to be recompiled: libxrender libxi libxfixes libxrandr libsdl1.2 libxv xserver-xorg-video-vmware cairo (see Debian sec tracker for current list). Probably we can release them independently one after the other but we should check that they don't break at the moment this libx11 update is rolled out.
The DSA version has been imported and built in errata4.0-1. Advisory: 2015-04-15-libx11.yaml All dependent packages have been cherrypicked from UCS-4.0-0 and rebuilt in errata4.0-1: libxfixes libxrandr libxext libsdl1.2 libxrender libxi libxv cairo wine-gecko-1.4 tightvnc xserver-xorg-video-vmware open-vm-tools texlive-bin libreoffice iceweasel (via Bug 38271). Corresponding advisories have been commited.
Installation: OK Tests: OK Advisories: OK
<http://errata.univention.de/ucs/4.0/169.html> <http://errata.univention.de/ucs/4.0/170.html> <http://errata.univention.de/ucs/4.0/171.html> <http://errata.univention.de/ucs/4.0/172.html> <http://errata.univention.de/ucs/4.0/173.html> <http://errata.univention.de/ucs/4.0/174.html> <http://errata.univention.de/ucs/4.0/175.html> <http://errata.univention.de/ucs/4.0/176.html> <http://errata.univention.de/ucs/4.0/177.html> <http://errata.univention.de/ucs/4.0/178.html> <http://errata.univention.de/ucs/4.0/179.html> <http://errata.univention.de/ucs/4.0/180.html> <http://errata.univention.de/ucs/4.0/181.html> <http://errata.univention.de/ucs/4.0/182.html> <http://errata.univention.de/ucs/4.0/192.html> <http://errata.univention.de/ucs/4.0/168.html>