[BACK]Return to errata55.html CVS log [TXT][DIR] Up to [local] / www

Diff for /www/errata55.html between version 1.14 and 1.15

version 1.14, 2014/05/02 17:43:48 version 1.15, 2014/05/24 09:50:42
Line 128 
Line 128 
 A source code patch exists which remedies this problem.</a>  A source code patch exists which remedies this problem.</a>
 <p>  <p>
   
   <li><a name="006_libXfont"></a>
   <font color="#009000"><strong>006: SECURITY FIX: May 24, 2014</strong></font>
   &nbsp; <i>All architectures with X server</i><br>
   X Font Service Protocol & Font metadata file handling issues in libXfont
   <ul>
   <li>CVE-2014-0209: integer overflow of allocations in font metadata file parsing
   <li>CVE-2014-0210: unvalidated length fields when parsing xfs protocol replies
   <li>CVE-2014-0211: integer overflows calculating memory needs for xfs replies
   </ul>
   Please see <a href="http://lists.x.org/archives/xorg-announce/2014-May/002431.html">the advisory</a> for more information.
   <br>
   <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.5/common/006_libXfont.patch.sig">
   A source code patch exists which remedies this problem.</a>
   <p>
   
 </ul>  </ul>
   
 </body>  </body>

Legend:
Removed from v.1.14  
changed lines
  Added in v.1.15