--------------------------------------------------------------------- Fedora Legacy Test Update Notification FEDORALEGACY-2005-2142 Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=2142 2005-02-09 ---------------------------------------------------------------------
Name : lesstif 7.3 Version : lesstif-0.93.18-2.2.legacy 9 Version : lesstif-0.93.36-3.2.legacy fc1 Version : lesstif-0.93.36-4.2.legacy Summary : An OSF/Motif(R) clone. Description : LessTif is a free replacement for OSF/Motif(R), which provides a full set of widgets for application development (menus, text entry areas, scrolling windows, etc.). LessTif is source compatible with OSF/Motif(R) 1.2. The widget set code is the primary focus of development. If you are installing lesstif, you also need to install lesstif-clients.
--------------------------------------------------------------------- Update Information:
Updated lesstif packages that fix flaws in the Xpm image library are now available.
lesstif is a free replacement for OSF/Motif(R), which provides a full set of widgets for application development.
During a source code audit, Chris Evans and others discovered several stack overflow flaws and an integer overflow flaw in the libXpm library used to decode XPM (X PixMap) images. A vulnerable version of this library was found within LessTif. An attacker could create a carefully crafted XPM file which would cause an application to crash or potentially execute arbitrary code if opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0687, CAN-2004-0688, and CAN-2004-0914 to these issues.
Users of lesstif are advised to upgrade to these erratum packages, which contain backported security patches to the embedded libXpm library.
--------------------------------------------------------------------- Changelogs:
rh73: * Fri Dec 03 2004 Rob Myers <rob myers gtri gatech edu> 0.93.18-2.2.legacy - apply diff from current lesstif cvs that removes the monolithic Xpm.c file and breaks it into the latest versions of the separate libXpm files. this should fix CAN-2004-0667, CAN-2004-0668, and CAN-2004-0914 (FL #2142)
rh9: * Fri Dec 03 2004 Rob Myers <rob myers gtri gatech edu> 0.93.36-3.2.legacy - apply diff from current lesstif cvs that removes the monolithic Xpm.c file and breaks it into the latest versions of the separate libXpm files. this should fix CAN-2004-0667, CAN-2004-0668, and CAN-2004-0914 (FL #2142)
fc1: * Fri Dec 03 2004 Rob Myers <rob myers gtri gatech edu> 0.93.36-4.2.legacy - apply diff from current lesstif cvs that removes the monolithic Xpm.c file and breaks it into the latest versions of the separate libXpm files. this should fix CAN-2004-0667, CAN-2004-0668, and CAN-2004-0914 (FL #2142)
--------------------------------------------------------------------- This update can be downloaded from: http://download.fedoralegacy.org/ (sha1sums)
Attachment:
signature.asc
Description: OpenPGP digital signature