Fedora Legacy Test Update Notification: openmotif

Marc Deslauriers marcdeslauriers at videotron.ca
Thu Feb 10 02:15:07 UTC 2005


---------------------------------------------------------------------
Fedora Legacy Test Update Notification
FEDORALEGACY-2005-2143
Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=2143
2005-02-09
---------------------------------------------------------------------

Name        : openmotif
7.3 Version : openmotif-2.2.2-5.2.legacy,
               openmotif21-2.1.30-1.2.legacy
9 Version   : openmotif-2.2.2-14.2.legacy,
               openmotif21-2.1.30-8.0.9.2.legacy
fc1 Version : openmotif-2.2.2-16.1.2.legacy,
               openmotif21-2.1.30-8.2.legacy
Summary     : Open Motif runtime libraries and executables.
Description :
This is the Open Motif 2.2.1 runtime environment. It includes the
Motif shared libraries, needed to run applications which are dynamically
linked against Motif, and the Motif Window Manager "mwm".

---------------------------------------------------------------------
Update Information:

Updated openmotif packages that fix flaws in the Xpm image library are
now available.

OpenMotif provides libraries which implement the Motif industry standard
graphical user interface.

During a source code audit, Chris Evans and others discovered several
stack overflow flaws and an integer overflow flaw in the libXpm library
used to decode XPM (X PixMap) images. A vulnerable version of this
library was found within OpenMotif. An attacker could create a carefully
crafted XPM file which would cause an application to crash or
potentially execute arbitrary code if opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0687, CAN-2004-0688, and CAN-2004-0914 to these issues.

Users of OpenMotif are advised to upgrade to these erratum packages,
which contain backported security patches to the embedded libXpm
library.

---------------------------------------------------------------------
openmotif21 changelogs:

rh73:
* Thu Dec 02 2004 Rob Myers <rob.myers at gtri.gatech.edu> 2.1.30-1.2.legacy
- apply patch for CAN-2004-0914 (FL #2143)
- use redhat's patch for CAN-2004-0687, CAN-2004-0688
- added BuildRequires: flex, byacc

* Thu Nov 04 2004 Rob Myers <rob.myers at gtri.gatech.edu> 2.1.30-1.1.legacy
- apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- added BuildRequires: automake, XFree86-devel

rh9:
* Wed Dec 01 2004 Rob Myers <rob.myers at gtri.gatech.edu> 
2.1.30-8.0.9.2.legacy
- apply patch for CAN-2004-0914 (FL #2143)
- use redhat's patch for CAN-2004-0687, CAN-2004-0688
- added BuildRequires: flex, byacc

* Thu Nov 04 2004 Rob Myers <rob.myers at gtri.gatech.edu>  2.1.30-8.1.legacy
- apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- added BuildRequires: automake, XFree86-devel

fc1:
* Wed Dec 01 2004 Rob Myers <rob.myers at gtri.gatech.edu>  2.1.30-8.2.legacy
- apply patch for CAN-2004-0914 (FL #2143)
- use redhat's patch for CAN-2004-0687, CAN-2004-0688
- added BuildRequires: flex, byacc

* Thu Nov 04 2004 Rob Myers <rob.myers at gtri.gatech.edu>  2.1.30-8.1.legacy
- apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- added BuildRequires: automake, XFree86-devel

openmotif changelogs:

rh73:
* Thu Dec 02 2004 Rob Myers <rob.myers at gtri.gatech.edu> 2.2.2-5.2.legacy
- apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143)
- use redhat's patch for CAN-2004-0687, CAN-2004-0688
- add patch to ltmain.sh to link properly

* Thu Nov 04 2004 Rob Myers <rob.myers at gtri.gatech.edu> 2.2.2-5.1.legacy
- apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- added BuildRequires: flex, byacc, XFree86-devel

rh9:
* Thu Dec 02 2004 Rob Myers <rob.myers at gtri.gatech.edu> 2.2.2-14.2.legacy
- apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143)
- use redhat's patch for CAN-2004-0687, CAN-2004-0688

* Thu Nov 04 2004 Rob Myers <rob.myers at gtri.gatech.edu> 2.2.2-14.1.legacy
- apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- add BuildPreReq: libtool, XFree86-devel


fc1:
* Thu Dec 02 2004 Rob Myers <rob.myers at gtri.gatech.edu> 2.2.2-16.1.2.legacy
- apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143)
- use redhat's patch for CAN-2004-0687, CAN-2004-0688

* Thu Nov 04 2004 Rob Myers <rob.myers at gtri.gatech.edu> 2.2.2-16.1.1.legacy
- apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- add BuildPreReq: libtool, XFree86-devel

---------------------------------------------------------------------
This update can be downloaded from:
   http://download.fedoralegacy.org/
(sha1sums)

fdb330d0eb404befeab472a98001c7a3e9a3a285 
redhat/7.3/updates-testing/i386/openmotif21-2.1.30-1.2.legacy.i386.rpm
069006be17df36fb8bdd4f3144922f2a82b3f255 
redhat/7.3/updates-testing/i386/openmotif-2.2.2-5.2.legacy.i386.rpm
a687cebff8a3bd4083953a127acc4c5aa47abd56 
redhat/7.3/updates-testing/i386/openmotif-devel-2.2.2-5.2.legacy.i386.rpm
015a88a9538a818261d0841a56d77be8135d80a9 
redhat/7.3/updates-testing/SRPMS/openmotif21-2.1.30-1.2.legacy.src.rpm
b21a945dc27b5a485f31acf2f9c30deb2fc4eddd 
redhat/7.3/updates-testing/SRPMS/openmotif-2.2.2-5.2.legacy.src.rpm
e215ee7469ba2087b03d92754703089fea7d3daf 
redhat/9/updates-testing/i386/openmotif21-2.1.30-8.0.9.2.legacy.i386.rpm
685a0ac8194730e6ccd4f56ae375052beca011b8 
redhat/9/updates-testing/i386/openmotif-2.2.2-14.2.legacy.i386.rpm
55805c44030bd081907ef461a9d752c16ec66907 
redhat/9/updates-testing/i386/openmotif-devel-2.2.2-14.2.legacy.i386.rpm
4ac7fe6bbc1c51cc954349fa7fb9428184d0da79 
redhat/9/updates-testing/SRPMS/openmotif21-2.1.30-8.0.9.2.legacy.src.rpm
4e4a5d7c2554a082075bbd7990aaa2c289cc74df 
redhat/9/updates-testing/SRPMS/openmotif-2.2.2-14.2.legacy.src.rpm
4b3d11f17b6997670140d6b39086050ea77928bc 
fedora/1/updates-testing/i386/openmotif21-2.1.30-8.2.legacy.i386.rpm
1e7c9aa8fa59add13c049193bfcadc6cf9f18613 
fedora/1/updates-testing/i386/openmotif-2.2.2-16.1.2.legacy.i386.rpm
14b5b94cad04f7d08e287651be552ff37adb38f8 
fedora/1/updates-testing/i386/openmotif-devel-2.2.2-16.1.2.legacy.i386.rpm
45fb3379e2a7c981bc5f7a43395bf793ba1135ac 
fedora/1/updates-testing/SRPMS/openmotif21-2.1.30-8.2.legacy.src.rpm
301a695b034118ceee64f92b0778a08919871374 
fedora/1/updates-testing/SRPMS/openmotif-2.2.2-16.1.2.legacy.src.rpm

---------------------------------------------------------------------

Please test and comment in bugzilla.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 256 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/fedora-legacy-list/attachments/20050209/9bd6e09f/attachment.sig>


More information about the fedora-legacy-list mailing list