Bug 11440 - [Update Request] Update x11-server to fix CVE-2013-4396
Summary: [Update Request] Update x11-server to fix CVE-2013-4396
Status: RESOLVED DUPLICATE of bug 11428
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 3
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard: MGA2TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-11 06:48 CEST by Funda Wang
Modified: 2013-10-11 10:27 CEST (History)
1 user (show)

See Also:
Source RPM: x11-server-1.13.4-2.2.mga3, x11-server-1.11.4-2.4.mga2
CVE: CVE-2013-4396
Status comment:


Attachments

Description Funda Wang 2013-10-11 06:48:04 CEST
Pedro Ribeiro reported an issue to the X.Org security team in which an authenticated X client can cause an X server to use memory after it was freed, potentially leading to crash and/or memory corruption.

The x11-server package have been patched to fix above problem (CVE-2013-4396).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4396
http://lists.x.org/archives/xorg-announce/2013-October/002332.html
https://bugzilla.redhat.com/show_bug.cgi?id=1014561

Reproducible: 

Steps to Reproduce:
Funda Wang 2013-10-11 06:48:29 CEST

CVE: (none) => CVE-2013-4396
Whiteboard: (none) => MGA2TOO

Funda Wang 2013-10-11 06:49:03 CEST

Source RPM: x11-server-1.13.4-2.2.mga3 => x11-server-1.13.4-2.2.mga3, x11-server-1.11.4-2.4.mga2

Comment 1 David Walser 2013-10-11 10:27:52 CEST
Thanks Funda.  We do already have a bug for this.

*** This bug has been marked as a duplicate of bug 11428 ***

Status: NEW => RESOLVED
CC: (none) => luigiwalser
Resolution: (none) => DUPLICATE


Note You need to log in before you can comment on or make changes to this bug.