-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-25329c196b 2023-12-05 16:27:20.051907 --------------------------------------------------------------------------------
Name : motif Product : Fedora 37 Version : 2.3.4 Release : 30.fc37 URL : http://www.motifzone.net/ Summary : Run-time libraries and programs Description : This is the Motif 2.3.4 run-time environment. It includes the Motif shared libraries, needed to run applications which are dynamically linked against Motif and the Motif Window Manager mwm.
-------------------------------------------------------------------------------- Update Information:
Security fix for CVE-2023-43788 and CVE-2023-43789 -------------------------------------------------------------------------------- ChangeLog:
* Mon Nov 27 2023 Jos�� Exp��sito jexposit@redhat.com - 2.3.4-30 - Fix CVE-2023-43788: out of bounds read in XpmCreateXpmImageFromBuffer() - Fix CVE-2023-43789: out of bounds read on XPM with corrupted colormap * Thu Jul 20 2023 Fedora Release Engineering releng@fedoraproject.org - 2.3.4-29 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Fri Apr 14 2023 Florian Weimer fweimer@redhat.com - 2.3.4-28 - Port to C99 (#2186773) * Thu Jan 19 2023 Fedora Release Engineering releng@fedoraproject.org - 2.3.4-27 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2242248 - CVE-2023-43788 libXpm: out of bounds read in XpmCreateXpmImageFromBuffer() https://bugzilla.redhat.com/show_bug.cgi?id=2242248 [ 2 ] Bug #2242249 - CVE-2023-43789 libXpm: out of bounds read on XPM with corrupted colormap https://bugzilla.redhat.com/show_bug.cgi?id=2242249 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-25329c196b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------