Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (20m)  pkgsrc-2024Q1 (10d)  pkgsrc-2023Q4 (57d)  pkgsrc-2023Q2 (89d)  pkgsrc-2023Q3 (169d) 

2024-05-28 02:25:38 UTC Now

2014-05-23 13:18:56 UTC MAIN commitmail json YAML

Apply openSUSE Security Update: openSUSE-SU-2014:0711-1
libXfont: Fixed multiple vulnerabilities

  An update that fixes three vulnerabilities is now available.

Description:

  libxfont was updated to fix multiple vulnerabilities:
  - Integer overflow of allocations in font metadata file parsing
    (CVE-2014-0209).
  - Unvalidated length fields when parsing xfs protocol replies
    (CVE-2014-0210).
  - Integer overflows calculating memory needs for xfs replies
    (CVE-2014-0211).

  These vulnerabilities could be used by a local, authenticated user to
  raise privileges
  or by a remote attacker with control of the font server to execute code
    with the privileges of the X server.

(obache)