OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
CVS: cvs.openbsd.org: XF4

From: Chris Kuethe (ckuethecvs.openbsd.org)
Date: Fri Apr 27 2007 - 23:55:02 CDT


CVSROOT: /cvs
Module name: XF4
Changes by: ckuethecvs.openbsd.org 2007/04/27 22:55:02

Modified files:
        xc/extras/freetype2/src/bdf: Tag: OPENBSD_4_1 bdflib.c
        xc/lib/X11 : Tag: OPENBSD_4_1 ImUtil.c
        xc/lib/font/bitmap: Tag: OPENBSD_4_1 bdfread.c
        xc/lib/font/fontfile: Tag: OPENBSD_4_1 fontdir.c
        xc/programs/Xserver/Xext: Tag: OPENBSD_4_1 xcmisc.c

Log message:
Multiple security fixes for X.Org:

- XC-MISC CVE-2007-1003

XC-MISC Extension ProcXCMiscGetXIDList Memory Corruption
Vulnerability

This vulnerability was discovered by Sean Larsson, iDefense Labs.

- bdf CVE-2007-1351

BDFFont Parsing Integer Overflow Vulnerability

The discoverer of this vulnerability wishes to remain anonymous.

- fontdir CVE-2007-1352

fonts.dir File Parsing Integer Overflow Vulnerability

The discoverer of this vulnerability wishes to remain anonymous.

- libX11 CVE-2007-1667

Multiple integer overflows in the XGetPixel() and XInitImage functions
in ImUtil.c