Summary: | Buffer overflow in XSecurityGenerateAuthorization | ||||||
---|---|---|---|---|---|---|---|
Product: | xorg | Reporter: | Rob <rob> | ||||
Component: | Security | Assignee: | X.Org Security <xorg_security> | ||||
Status: | RESOLVED FIXED | QA Contact: | X.Org Security <xorg_security> | ||||
Severity: | normal | ||||||
Priority: | medium | ||||||
Version: | unspecified | ||||||
Hardware: | Other | ||||||
OS: | All | ||||||
Whiteboard: | |||||||
i915 platform: | i915 features: | ||||||
Attachments: |
|
Description
Rob
2016-02-25 17:30:17 UTC
Thanks - fix has been pushed to git master: https://cgit.freedesktop.org/xorg/lib/libXext/commit/?id=0744837f525d8ba103e807af7c44ad2bf5cbd6ca Also, for the public record, from the X.Org Security list discussion: The description and proposed patch seem correct, but I do not believe we need to issue a security bulletin or request a CVE, as I don't see any existing calls to this library from privileged code. https://codesearch.debian.net/results/XSecurityGenerateAuthorization/page_0 only finds calls to it from xauth or xrx in the X code base. |
Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.