Fedora Legacy Test Update Notification: lesstif

Marc Deslauriers marcdeslauriers at videotron.ca
Thu Feb 10 02:14:24 UTC 2005


---------------------------------------------------------------------
Fedora Legacy Test Update Notification
FEDORALEGACY-2005-2142
Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=2142
2005-02-09
---------------------------------------------------------------------

Name        : lesstif
7.3 Version : lesstif-0.93.18-2.2.legacy
9 Version   : lesstif-0.93.36-3.2.legacy
fc1 Version : lesstif-0.93.36-4.2.legacy
Summary     : An OSF/Motif(R) clone.
Description :
LessTif is a free replacement for OSF/Motif(R), which provides a full
set of widgets for application development (menus, text entry areas,
scrolling windows, etc.). LessTif is source compatible with
OSF/Motif(R) 1.2. The widget set code is the primary focus of
development. If you are installing lesstif, you also need to install
lesstif-clients.

---------------------------------------------------------------------
Update Information:

Updated lesstif packages that fix flaws in the Xpm image library are
now available.

lesstif is a free replacement for OSF/Motif(R), which provides a full
set of widgets for application development.

During a source code audit, Chris Evans and others discovered several
stack overflow flaws and an integer overflow flaw in the libXpm library
used to decode XPM (X PixMap) images. A vulnerable version of this
library was found within LessTif. An attacker could create a carefully
crafted XPM file which would cause an application to crash or
potentially execute arbitrary code if opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0687, CAN-2004-0688, and CAN-2004-0914 to these issues.

Users of lesstif are advised to upgrade to these erratum packages,
which contain backported security patches to the embedded libXpm
library.

---------------------------------------------------------------------
Changelogs:

rh73:
* Fri Dec 03 2004 Rob Myers <rob.myers at gtri.gatech.edu> 0.93.18-2.2.legacy
- apply diff from current lesstif cvs that removes the monolithic
   Xpm.c file and breaks it into the latest versions of the separate
   libXpm files.  this should fix  CAN-2004-0667, CAN-2004-0668, and
   CAN-2004-0914 (FL #2142)

rh9:
* Fri Dec 03 2004 Rob Myers <rob.myers at gtri.gatech.edu> 0.93.36-3.2.legacy
- apply diff from current lesstif cvs that removes the monolithic
   Xpm.c file and breaks it into the latest versions of the separate
   libXpm files.  this should fix  CAN-2004-0667, CAN-2004-0668, and
   CAN-2004-0914 (FL #2142)

fc1:
* Fri Dec 03 2004 Rob Myers <rob.myers at gtri.gatech.edu> 0.93.36-4.2.legacy
- apply diff from current lesstif cvs that removes the monolithic
   Xpm.c file and breaks it into the latest versions of the separate
   libXpm files.  this should fix  CAN-2004-0667, CAN-2004-0668, and
   CAN-2004-0914 (FL #2142)

---------------------------------------------------------------------
This update can be downloaded from:
   http://download.fedoralegacy.org/
(sha1sums)

26c3a96c2a96318a571a764bf6cbcc2da51b864e 
redhat/7.3/updates-testing/i386/lesstif-0.93.18-2.2.legacy.i386.rpm
67cdd0f2ddcedd779b72dbe56a8a8b14c78776a5 
redhat/7.3/updates-testing/i386/lesstif-devel-0.93.18-2.2.legacy.i386.rpm
d5547933d225e222b84a214bc8da59f914b4daaa 
redhat/7.3/updates-testing/SRPMS/lesstif-0.93.18-2.2.legacy.src.rpm
acd0cd8114977e042b846ed551dc3bbc4bceb5da 
redhat/9/updates-testing/i386/lesstif-0.93.36-3.2.legacy.i386.rpm
2214729452e380e0d7f792a44fb319f570b8cb92 
redhat/9/updates-testing/i386/lesstif-devel-0.93.36-3.2.legacy.i386.rpm
555602673a35a96b35d4409eab2a6ce34b431588 
redhat/9/updates-testing/SRPMS/lesstif-0.93.36-3.2.legacy.src.rpm
8eb15fc40c444e4b23c2400d83716b80d13ce338 
fedora/1/updates-testing/i386/lesstif-0.93.36-4.2.legacy.i386.rpm
88ac0f340f86dd7030a78d77d8d8b8570c614a55 
fedora/1/updates-testing/i386/lesstif-devel-0.93.36-4.2.legacy.i386.rpm
57b16fc90fd0dadd13f2db2899de976e1f4c08aa 
fedora/1/updates-testing/SRPMS/lesstif-0.93.36-4.2.legacy.src.rpm

---------------------------------------------------------------------

Please test and comment in bugzilla.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 256 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/fedora-legacy-list/attachments/20050209/1f600156/attachment.sig>


More information about the fedora-legacy-list mailing list