Bug 11440

Summary: [Update Request] Update x11-server to fix CVE-2013-4396
Product: Mageia Reporter: Funda Wang <fundawang>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: luigiwalser
Version: 3   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4396
Whiteboard: MGA2TOO
Source RPM: x11-server-1.13.4-2.2.mga3, x11-server-1.11.4-2.4.mga2 CVE: CVE-2013-4396
Status comment:

Description Funda Wang 2013-10-11 06:48:04 CEST
Pedro Ribeiro reported an issue to the X.Org security team in which an authenticated X client can cause an X server to use memory after it was freed, potentially leading to crash and/or memory corruption.

The x11-server package have been patched to fix above problem (CVE-2013-4396).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4396
http://lists.x.org/archives/xorg-announce/2013-October/002332.html
https://bugzilla.redhat.com/show_bug.cgi?id=1014561

Reproducible: 

Steps to Reproduce:
Funda Wang 2013-10-11 06:48:29 CEST

CVE: (none) => CVE-2013-4396
Whiteboard: (none) => MGA2TOO

Funda Wang 2013-10-11 06:49:03 CEST

Source RPM: x11-server-1.13.4-2.2.mga3 => x11-server-1.13.4-2.2.mga3, x11-server-1.11.4-2.4.mga2

Comment 1 David Walser 2013-10-11 10:27:52 CEST
Thanks Funda.  We do already have a bug for this.

*** This bug has been marked as a duplicate of bug 11428 ***

Status: NEW => RESOLVED
CC: (none) => luigiwalser
Resolution: (none) => DUPLICATE