[SECURITY] Fedora 9 Update: xorg-x11-server-1.4.99.902-3.20080612.fc9

updates at fedoraproject.org updates at fedoraproject.org
Sat Jun 14 04:15:37 UTC 2008


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2008-5254
2008-06-14 01:18:53
--------------------------------------------------------------------------------

Name        : xorg-x11-server
Product     : Fedora 9
Version     : 1.4.99.902
Release     : 3.20080612.fc9
URL         : http://www.x.org
Summary     : X.Org X11 X server
Description :
X.Org X11 X server

--------------------------------------------------------------------------------
Update Information:

For further details, see X.org security advisory:
http://lists.freedesktop.org/archives/xorg/2008-June/036026.html
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jun 12 2008 Dave Airlie <airlied at redhat.com> 1.4.99.902-3.20080612
- xserver-1.5.0-fix-single-aspect.patch - fix 2560x1600 on my monitor.
* Thu Jun 12 2008 Dave Airlie <airlied at redhat.com> 1.4.99.902-2.20080612
- cve-2008-1377: Record and Security Extension Input validation
- cve-2008-1379: MIT-SHM extension Input Validation flaw
- cve-2008-2360: Render AllocateGlyph extension Integer overflows
- cve-2008-2361: Render CreateCursor extension Integer overflows
- cve-2008-2362: Render Gradient extension Integer overflows
- Rebase to 1.5 head for security patches for above
* Mon Jun  9 2008 Adam Jackson <ajax at redhat.com> 1.4.99.902-1.20080609
- Today's git snapshot.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #448783 - CVE-2008-2360 X.org Render extension AllocateGlyph() heap buffer overflow
        https://bugzilla.redhat.com/show_bug.cgi?id=448783
  [ 2 ] Bug #448784 - CVE-2008-2361 X.org Render extension ProcRenderCreateCursor() crash
        https://bugzilla.redhat.com/show_bug.cgi?id=448784
  [ 3 ] Bug #448785 - CVE-2008-2362 X.org Render extension input validation flaw causing memory corruption
        https://bugzilla.redhat.com/show_bug.cgi?id=448785
  [ 4 ] Bug #445414 - CVE-2008-1379 X.org MIT-SHM extension arbitrary memory read
        https://bugzilla.redhat.com/show_bug.cgi?id=445414
  [ 5 ] Bug #445403 - CVE-2008-1377 X.org Record and Security extensions memory corruption
        https://bugzilla.redhat.com/show_bug.cgi?id=445403
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update xorg-x11-server' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------




More information about the package-announce mailing list