From owner-cvs-all@FreeBSD.ORG Sat Mar 6 13:53:44 2004 Return-Path: Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 47D6B16A4CF; Sat, 6 Mar 2004 13:53:44 -0800 (PST) Received: from gw.celabo.org (gw.celabo.org [208.42.49.153]) by mx1.FreeBSD.org (Postfix) with ESMTP id C6FC143D3F; Sat, 6 Mar 2004 13:53:43 -0800 (PST) (envelope-from nectar@celabo.org) Received: from madman.celabo.org (madman.celabo.org [10.0.1.111]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "madman.celabo.org", Issuer "celabo.org CA" (verified OK)) by gw.celabo.org (Postfix) with ESMTP id 3B61654840; Sat, 6 Mar 2004 15:53:43 -0600 (CST) Received: by madman.celabo.org (Postfix, from userid 1001) id D3D456D465; Sat, 6 Mar 2004 15:53:42 -0600 (CST) Date: Sat, 6 Mar 2004 15:53:42 -0600 From: "Jacques A. Vidrine" To: Trevor Johnson Message-ID: <20040306215342.GA91865@madman.celabo.org> Mail-Followup-To: "Jacques A. Vidrine" , Trevor Johnson , Dag-Erling Smørgrav , Trevor Johnson , ports-committers@FreeBSD.org, cvs-ports@FreeBSD.org, cvs-all@FreeBSD.org References: <200403041722.i24HMSLN083120@repoman.freebsd.org> <20040306153749.R55348@blues.jpj.net> Mime-Version: 1.0 Content-Type: text/plain; charset=unknown-8bit Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20040306153749.R55348@blues.jpj.net> X-Url: http://www.celabo.org/ User-Agent: Mutt/1.5.6i cc: Dag-Erling Smørgrav cc: cvs-ports@FreeBSD.org cc: Trevor Johnson cc: cvs-all@FreeBSD.org cc: ports-committers@FreeBSD.org Subject: Re: cvs commit: ports/x11/linux-XFree86-libs Makefile distinfo.i386 X-BeenThere: cvs-all@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the entire tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 06 Mar 2004 21:53:44 -0000 On Sat, Mar 06, 2004 at 04:17:23PM -0500, Trevor Johnson wrote: > Dag-Erling [iso-8859-1] Smørgrav wrote: > > > Trevor Johnson writes: > > > Log: > > > Update to version 4.3.0-2.90.55 due to several security bugs > > > (discovered by iDefense and David Dawes) in the parsing of font > > > files and the font.alias file which can give root privileges to > > > local users. [...] > > > > This is pointless as the bug in question only affects the server. > > I hadn't noticed that--when I glanced at > , which > addresses these bugs, it looked like the problem was in the X libraries, > not the server. [...] The bugs *are* in a library (libXfont), but one could only exploit them for privilege escalation in the server (which has libXfont compiled internally). I added linux-XFree86-libs to the VuXML entry describing this vulnerability (http://www.vuxml.org/freebsd/3837f462-5d6b-11d8-80e3-0020ed76ef5a.html) without thinking too much. Should I remove it? Cheers, -- Jacques Vidrine / nectar@celabo.org / jvidrine@verio.net / nectar@freebsd.org