pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: [pkgsrc-2013Q2] pkgsrc/x11/libXi

Module Name:    pkgsrc
Committed By:   tron
Date:           Mon Jul 15 19:41:34 UTC 2013

Modified Files:
        pkgsrc/x11/libXi [pkgsrc-2013Q2]: Makefile distinfo

Log Message:
Pullup ticket #4177 - requested by taca
x11/libXi: security update

Revisions pulled up:
- x11/libXi/Makefile                                            1.24
- x11/libXi/distinfo                                            1.20

   Module Name: pkgsrc
   Committed By:        wiz
   Date:                Wed Jul  3 06:27:03 UTC 2013

   Modified Files:
        pkgsrc/x11/libXi: Makefile distinfo

   Log Message:
   Update to 1.7.2.

   Changes in 1.7.2:
   Only one minor change since the RC. Again, this release contains the fixes
   for CVE-2013-1998, CVE-2013-1984 and CVE-2013-1995 so you're encouraged to

   Peter Hutterer (1):
         libXi 1.7.2

   Thomas Klausner (1):
         Remove check that can never be true.

   Changses in
   First and likely only RC for libXi 1.7.2. This one has a bunch of changes
   for CVE-2013-1998, CVE-2013-1984 and CVE-2013-1995. These relate to various
   integer overflows and other corruption that happens if we trust the server
   a bit too much on the data we're being sent.

   On top of those fixes, the sequence number in XI2 events is now set
   propertly too (#64687).

   Please test, if you find any issues let me know.

   Alan Coopersmith (14):
         Expand comment on the memory vs. reply ordering in 
         Use _XEatDataWords to avoid overflow of rep.length bit shifting
         Stack buffer overflow in XGetDeviceButtonMapping() [CVE-2013-1998 1/3]
         memory corruption in _XIPassiveGrabDevice() [CVE-2013-1998 2/3]
         unvalidated lengths in XQueryDeviceState() [CVE-2013-1998 3/3]
         integer overflow in XGetDeviceControl() [CVE-2013-1984 1/8]
         integer overflow in XGetFeedbackControl() [CVE-2013-1984 2/8]
         integer overflow in XGetDeviceDontPropagateList() [CVE-2013-1984 3/8]
         integer overflow in XGetDeviceMotionEvents() [CVE-2013-1984 4/8]
         integer overflow in XIGetProperty() [CVE-2013-1984 5/8]
         integer overflow in XIGetSelectedEvents() [CVE-2013-1984 6/8]
         Avoid integer overflow in XGetDeviceProperties() [CVE-2013-1984 7/8]
         Avoid integer overflow in XListInputDevices() [CVE-2013-1984 8/8]
         sign extension issue in XListInputDevices() [CVE-2013-1995]

   Peter Hutterer (7):
         Copy the sequence number into the target event too (#64687)
         Don't overwrite the cookies serial number
         Fix potential corruption in mask_len handling
         Change size += to size = in XGetDeviceControl
         If the XGetDeviceDontPropagateList reply has an invalid length, return 0
         Include limits.h to prevent build error: missing INT_MAX

To generate a diff of this commit:
cvs rdiff -u -r1.23 -r1.23.2.1 pkgsrc/x11/libXi/Makefile
cvs rdiff -u -r1.19 -r1.19.2.1 pkgsrc/x11/libXi/distinfo

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Home | Main Index | Thread Index | Old Index