Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 29 Oct 2015 13:05:50 -0400 (EDT)
From: cve-assign@...re.org
To: mtasaka@...oraproject.org
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: CVE request: xscreensaver aborts when unpluging second monitor cable when asking password

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> https://bugzilla.redhat.com/show_bug.cgi?id=1274452
> https://twitter.com/Thaolia/status/656823859304398848
> http://pkgs.fedoraproject.org/cgit/xscreensaver.git/diff/xscreensaver-5.33-0002-Modify-sigchld_hander-in_signal_hander_p-mechanism.patch?id=b57f59f3482fedf70ce7a3541094e2512290139f
> https://www.jwz.org/blog/2015/10/xscreensaver-5-34/

> xscreensaver-5.33/driver/subprocs.c

>> The proximate cause was that an internal consistency check failed
>> because I meant to be checking "am I running on the signal stack?" but
>> I was checking "is the SIGCHLD signal currently inhibited?" instead.

Use CVE-2015-8025.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJWMlGVAAoJEL54rhJi8gl5cbsP/iOTyk0Dxi4iqiRckHQUOJTT
PF15byPeuiGq2A1Hg1gGVjKztsAdkXVBp12wz2ABNWYP/1us976Sb4pHdGHI2dOc
DAMOpZooBxcLl44xfdvQ4IBhFzQ82oFM4Udm8YuM1fzKvrCVuk25rKdravnhSqgs
+5zXxSjiFJ8iHIAQB7RVVvK2vMCY9CR0OjZ6O9vo9ZMrmT75ERZ8obLDYnCVI7CI
BTRz6/mp+JHjs51t+nuxD3n5t6j/hKIcmDDjeEwPOf6emCduJplrTLBN4Px53seT
/zUZtK3JQeFSMuj+A/TR9RqCoUIAdrB38qs5wkOyRtzKGO/QcQYZ/n5G2ufx1BjX
THGZDVEYyEz7YOUW3eMKGpeFM58JhrKWaL8F4fXgAZOfrdwuoNdh3YqPfYYkfKDk
i4pHX/WWTV8tqo7Vz5cmoW4l74+xcTvP9TE0IbBZz9ZjT4runf17OktKrrJJKCkz
y6WzY8MaX6Q5Ua2Zvl2CORLBCD3rIqsWkXFa2tdQimqKDxQ1+T5BDTrgP4P50drw
5v9HcPtRKoTBKu0ovxKMC47/vOdHX39KKfvOXP7+NR5md3NcneGFEi5zAYPSc8qb
gH2cxqcw0FslrZm+5n9ufJIBCc5rDkQewyUqtzv90pzL97FOfqjgVHuHZuoF/Dip
WpYCibKW9zQ2/lFfnLRN
=vSZ7
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.