Fedora alert FEDORA-2008-5254 (xorg-x11-server)
From: | updates@fedoraproject.org | |
To: | fedora-package-announce@redhat.com | |
Subject: | [SECURITY] Fedora 9 Update: xorg-x11-server-1.4.99.902-3.20080612.fc9 | |
Date: | Sat, 14 Jun 2008 04:15:37 +0000 | |
Message-ID: | <200806140415.m5E4F3XO015007@bastion.fedora.phx.redhat.com> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-5254 2008-06-14 01:18:53 -------------------------------------------------------------------------------- Name : xorg-x11-server Product : Fedora 9 Version : 1.4.99.902 Release : 3.20080612.fc9 URL : http://www.x.org Summary : X.Org X11 X server Description : X.Org X11 X server -------------------------------------------------------------------------------- Update Information: For further details, see X.org security advisory: http://lists.freedesktop.org/archives/xorg/2008-June/0360... -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 12 2008 Dave Airlie <airlied@redhat.com> 1.4.99.902-3.20080612 - xserver-1.5.0-fix-single-aspect.patch - fix 2560x1600 on my monitor. * Thu Jun 12 2008 Dave Airlie <airlied@redhat.com> 1.4.99.902-2.20080612 - cve-2008-1377: Record and Security Extension Input validation - cve-2008-1379: MIT-SHM extension Input Validation flaw - cve-2008-2360: Render AllocateGlyph extension Integer overflows - cve-2008-2361: Render CreateCursor extension Integer overflows - cve-2008-2362: Render Gradient extension Integer overflows - Rebase to 1.5 head for security patches for above * Mon Jun 9 2008 Adam Jackson <ajax@redhat.com> 1.4.99.902-1.20080609 - Today's git snapshot. -------------------------------------------------------------------------------- References: [ 1 ] Bug #448783 - CVE-2008-2360 X.org Render extension AllocateGlyph() heap buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=448783 [ 2 ] Bug #448784 - CVE-2008-2361 X.org Render extension ProcRenderCreateCursor() crash https://bugzilla.redhat.com/show_bug.cgi?id=448784 [ 3 ] Bug #448785 - CVE-2008-2362 X.org Render extension input validation flaw causing memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=448785 [ 4 ] Bug #445414 - CVE-2008-1379 X.org MIT-SHM extension arbitrary memory read https://bugzilla.redhat.com/show_bug.cgi?id=445414 [ 5 ] Bug #445403 - CVE-2008-1377 X.org Record and Security extensions memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=445403 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update xorg-x11-server' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...