Summary: | x11-base/xorg-server Multiple vulnerabilities in X server extensions (CVE-2008-1377, CVE-2008-1379, CVE-2008-2360, CVE-2008-2361, CVE-2008-2362) | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | Gentoo Security | Reporter: | Matthias Geerdsen (RETIRED) <vorlon> | ||||||||||||||
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> | ||||||||||||||
Status: | RESOLVED FIXED | ||||||||||||||||
Severity: | critical | CC: | x11 | ||||||||||||||
Priority: | High | ||||||||||||||||
Version: | unspecified | ||||||||||||||||
Hardware: | All | ||||||||||||||||
OS: | Linux | ||||||||||||||||
URL: | http://lists.freedesktop.org/archives/xorg/2008-June/036026.html | ||||||||||||||||
Whiteboard: | A1 [glsa] | ||||||||||||||||
Package list: | Runtime testing required: | --- | |||||||||||||||
Attachments: |
|
Description
Matthias Geerdsen (RETIRED)
![]() Created attachment 155985 [details, diff]
cve-2008-1377
Created attachment 155987 [details, diff]
cve-2008-1379
Created attachment 155989 [details, diff]
cve-2008-2360
Created attachment 155991 [details, diff]
cve-2008-2361
Created attachment 155993 [details, diff]
cve-2008-2362
Donnie, please prepare an updated ebuild and attach it here so we can have the arch security liaisons test it. Please do not commit anything to the tree yet as this is still confidential. and for the draft here is the credit section of the advisory: Credits These vulnerabilities were reported to iDefense by regenrecht. Just for future reference, as X maintainer I am far too familiar with security vulnerabilities, so you don't need to walk me through the process. =) I also have access to the upstream security bugs, so I can follow things there. I'll see if I can get ebuilds up here later today. (In reply to comment #7) > Just for future reference, as X maintainer I am far too familiar with security > vulnerabilities, so you don't need to walk me through the process. =) I also > have access to the upstream security bugs, so I can follow things there. While I don't doubt your full reliability when handling these kinds of issues, this is just what our template bugs look like. Also, there are other people reading these bugs (like arch liaisons and others in CC), and we just try to minimize errors by maximizing clarity. Thanks for speaking up, and sorry if this increases your effort in reading the bug. Created attachment 156325 [details]
xorg-server.tar.bz2
This is a tarball of the xorg-server directory. Unpack it from x11-base/. It contains xorg-server-1.3.0.0-r6.ebuild and xorg-server-1.4.1.ebuild. (Sorry I didn't get to this last night.)
thanks donnie Arch Security Liaisons, please test the attached ebuild and report it stable on this bug. CC'ing current Liaisons: alpha : yoswink amd64 : welp hppa : jer ppc : dertobi123 ppc64 : corsair release : pva sparc : fmccor x86 : opfer Quick handling of this would be appreciated, since this is rated A1 and supposed to be made public soon. for ppc64: adding ranger to cc, as my internet connection is currently very limited... x86 good to go for 1.3x series, I have no setup for 1.4, but it is ~arch anyway. 1.3 looks okay on alpha/ia64/sparc These are now public and in the tree, and I've stabilized 1.3.0.0-r6 on the tested arches (x86/alpha/ia64/sparc). Other arches, please stabilize in the tree. public via $URL removing arch liaisons and adding aliases please test and mark stable really adding arch aliases now... Please test x11-base/xorg-server-1.3.0.0-r6 and mark stable if possible. As a local root vulnerability this should be dealt with quickly. ppc64 done ppc stable amd64, would you like me to stabilize this for you? I'm running ~amd64 so I don't have a pure stable setup, though. amd64 stable Stable for HPPA. Fixed in release snapshot. This is GLSA 200806-07 thanks everyone |