|
|
Message-ID: <e4e38e9c-370a-4b4e-a525-101d1f68e9e7@oracle.com>
Date: Tue, 3 Oct 2023 13:16:44 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Cc: "X.Org Security Team" <xorg-security@...ts.x.org>
Subject: Re: Fwd: X.Org Security Advisory: Issues in libX11 prior to 1.8.7 &
libXpm prior to 3.5.17
On 10/3/23 09:31, Alan Coopersmith wrote:
> X.Org Security Advisory: October 3, 2023
>
> Issues in libX11 prior to 1.8.7 & libXpm prior to 3.5.17
> ========================================================
Two additional things we shared with the distros list pre-disclosure:
1) Test cases for 3 of the XPM bugs - instead of attaching them to the emails
to test which of your mail readers are still vulnerable to these bugs,
we've checked them in to the libXpm git repo - see the commits starting
with "test" listed on:
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commits/libXpm-3.5.17?ref_type=tags
(The test case for CVE-2023-43788 was already in the repo from
CVE-2022-46285 from earlier this year).
2) When Dr. Duck reported the libX11 issue included in this set as
CVE-2023-43785 he also reported several other bugs as potential
security issues. We determined they did not meet our vulnerability
criteria but fixed them as general bugs and improved hardening.
If you are backporting individual patches instead of upgrading to
the new releases, you may want to consider if they meet your criteria
for backporting as well:
https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/233
https://gitlab.freedesktop.org/xorg/lib/libxrandr/-/merge_requests/6
https://gitlab.freedesktop.org/xorg/app/xrandr/-/merge_requests/12
Each merge request contains a comment with our reasoning.
Of course, our releases also contain other bug fixes & hardening besides
those listed here.
--
-Alan Coopersmith- alan.coopersmith@...cle.com
X.Org Security Response Team - xorg-security@...ts.x.org
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.