--------------------------------------------------------------------- Fedora Legacy Test Update Notification FEDORALEGACY-2005-2143 Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=2143 2005-02-09 ---------------------------------------------------------------------
Name : openmotif
7.3 Version : openmotif-2.2.2-5.2.legacy,
openmotif21-2.1.30-1.2.legacy
9 Version : openmotif-2.2.2-14.2.legacy,
openmotif21-2.1.30-8.0.9.2.legacy
fc1 Version : openmotif-2.2.2-16.1.2.legacy,
openmotif21-2.1.30-8.2.legacy
Summary : Open Motif runtime libraries and executables.
Description :
This is the Open Motif 2.2.1 runtime environment. It includes the
Motif shared libraries, needed to run applications which are dynamically
linked against Motif, and the Motif Window Manager "mwm".--------------------------------------------------------------------- Update Information:
Updated openmotif packages that fix flaws in the Xpm image library are now available.
OpenMotif provides libraries which implement the Motif industry standard graphical user interface.
During a source code audit, Chris Evans and others discovered several stack overflow flaws and an integer overflow flaw in the libXpm library used to decode XPM (X PixMap) images. A vulnerable version of this library was found within OpenMotif. An attacker could create a carefully crafted XPM file which would cause an application to crash or potentially execute arbitrary code if opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0687, CAN-2004-0688, and CAN-2004-0914 to these issues.
Users of OpenMotif are advised to upgrade to these erratum packages, which contain backported security patches to the embedded libXpm library.
--------------------------------------------------------------------- openmotif21 changelogs:
rh73: * Thu Dec 02 2004 Rob Myers <rob myers gtri gatech edu> 2.1.30-1.2.legacy - apply patch for CAN-2004-0914 (FL #2143) - use redhat's patch for CAN-2004-0687, CAN-2004-0688 - added BuildRequires: flex, byacc
* Thu Nov 04 2004 Rob Myers <rob myers gtri gatech edu> 2.1.30-1.1.legacy - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143) - added BuildRequires: automake, XFree86-devel
* Thu Nov 04 2004 Rob Myers <rob myers gtri gatech edu> 2.1.30-8.1.legacy - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143) - added BuildRequires: automake, XFree86-devel
fc1: * Wed Dec 01 2004 Rob Myers <rob myers gtri gatech edu> 2.1.30-8.2.legacy - apply patch for CAN-2004-0914 (FL #2143) - use redhat's patch for CAN-2004-0687, CAN-2004-0688 - added BuildRequires: flex, byacc
* Thu Nov 04 2004 Rob Myers <rob myers gtri gatech edu> 2.1.30-8.1.legacy - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143) - added BuildRequires: automake, XFree86-devel
rh73: * Thu Dec 02 2004 Rob Myers <rob myers gtri gatech edu> 2.2.2-5.2.legacy - apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143) - use redhat's patch for CAN-2004-0687, CAN-2004-0688 - add patch to ltmain.sh to link properly
* Thu Nov 04 2004 Rob Myers <rob myers gtri gatech edu> 2.2.2-5.1.legacy - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143) - added BuildRequires: flex, byacc, XFree86-devel
rh9: * Thu Dec 02 2004 Rob Myers <rob myers gtri gatech edu> 2.2.2-14.2.legacy - apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143) - use redhat's patch for CAN-2004-0687, CAN-2004-0688
* Thu Nov 04 2004 Rob Myers <rob myers gtri gatech edu> 2.2.2-14.1.legacy - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143) - add BuildPreReq: libtool, XFree86-devel
fc1: * Thu Dec 02 2004 Rob Myers <rob myers gtri gatech edu> 2.2.2-16.1.2.legacy - apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143) - use redhat's patch for CAN-2004-0687, CAN-2004-0688
* Thu Nov 04 2004 Rob Myers <rob myers gtri gatech edu> 2.2.2-16.1.1.legacy - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143) - add BuildPreReq: libtool, XFree86-devel
--------------------------------------------------------------------- This update can be downloaded from: http://download.fedoralegacy.org/ (sha1sums)
Attachment:
signature.asc
Description: OpenPGP digital signature