| Summary: | libxfont new security issues CVE-2015-180[2-4] | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | olchal, rverschelde, sysadmin-bugs |
| Version: | 4 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/637024/ | ||
| Whiteboard: | has_procedure MGA4-32-OK MGA4-64-OK advisory | ||
| Source RPM: | libxfont-1.4.7-1.1.mga4.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2015-03-17 22:02:18 CET
Debian has issued an advisory for this today (March 17): https://lists.debian.org/debian-security-announce/2015/msg00079.html The DSA will be posted here: https://www.debian.org/security/2015/dsa-3194 URL:
(none) =>
http://lwn.net/Vulnerabilities/637024/
David Walser
2015-03-18 16:49:54 CET
Severity:
normal =>
major I think the best way to test this is to engage its bdf font parser, which is used by the bdftopcf command/package. # urpmi icewm-themes bdftopcf $ file /usr/share/X11/icewm/themes/miggy4/helvetica_amiga.bdf /usr/share/X11/icewm/themes/miggy4/helvetica_amiga.bdf: X11 BDF font, ASCII text $ bdftopcf /usr/share/X11/icewm/themes/miggy4/helvetica_amiga.bdf > helvetica_amiga.pcf $ file helvetica_amiga.pcf helvetica_amiga.pcf: X11 Portable Compiled Font data Testing complete Mageia 4 i586. Whiteboard:
(none) =>
has_procedure MGA4-32-OK Testing on Mageia 4x64 real hardware, using procedure from Comment 2 From current package : lib64xfont1-1.4.7-1.1.mga4 To updated testing package : lib64xfont1-1.4.7-1.2.mga4 All OK with David's procedure. CC:
(none) =>
olchal Advisory uploaded, validating. Please push to 4 core/updates. Keywords:
(none) =>
validated_update An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGASA-2015-0113.html Status:
NEW =>
RESOLVED |