Subject: CVS commit: [netbsd-4] xsrc
To: None <source-changes@NetBSD.org>
From: Manuel Bouyer <bouyer@netbsd.org>
List: source-changes
Date: 04/06/2007 18:34:24
Module Name:	xsrc
Committed By:	bouyer
Date:		Fri Apr  6 18:34:23 UTC 2007

Modified Files:
	xsrc/xfree/xc/lib/X11 [netbsd-4]: ImUtil.c
	xsrc/xfree/xc/lib/font/bitmap [netbsd-4]: bdfread.c
	xsrc/xfree/xc/lib/font/fontfile [netbsd-4]: fontdir.c
	xsrc/xfree/xc/programs/Xserver/Xext [netbsd-4]: xcmisc.c
	xsrc/xorg/lib/X11/src [netbsd-4]: ImUtil.c
	xsrc/xorg/lib/Xfont/src/bitmap [netbsd-4]: bdfread.c
	xsrc/xorg/lib/Xfont/src/fontfile [netbsd-4]: fontdir.c
	xsrc/xorg/xserver/xorg/Xext [netbsd-4]: xcmisc.c

Log Message:
Pull up following revision(s) (requested by drochner in ticket #555):
	xorg/xserver/xorg/Xext/xcmisc.c: revision 1.2
	xorg/lib/Xfont/src/fontfile/fontdir.c: revision 1.2
	xorg/lib/X11/src/ImUtil.c: revision 1.2
	xfree/xc/lib/X11/ImUtil.c: revision 1.2
	xfree/xc/lib/font/fontfile/fontdir.c: revision 1.2
	xfree/xc/programs/Xserver/Xext/xcmisc.c: revision 1.2
	xfree/xc/lib/font/bitmap/bdfread.c: revision 1.2
	xorg/lib/Xfont/src/bitmap/bdfread.c: revision 1.2
fix a possible memory corruption due to integer overflow in
ProcXCMiscGetXIDList() (CVE-2007-1003)
fix a possible memory corruption due to integer overflow, caused by lack
of validation of bdf font files (CVE 2007-1351)
fix a possible memory corruption due to integer overflow, caused by lack
of validation of fonts.dir files (CVE 2007-1352)
fix a possible memory corruption due to incomplete input validation in
XInitImage() (CVE 2007-1667)


To generate a diff of this commit:
cvs rdiff -r1.1.1.5 -r1.1.1.5.16.1 xsrc/xfree/xc/lib/X11/ImUtil.c
cvs rdiff -r1.1.1.6 -r1.1.1.6.16.1 xsrc/xfree/xc/lib/font/bitmap/bdfread.c
cvs rdiff -r1.1.1.7 -r1.1.1.7.16.1 xsrc/xfree/xc/lib/font/fontfile/fontdir.c
cvs rdiff -r1.1.1.5 -r1.1.1.5.16.1 \
    xsrc/xfree/xc/programs/Xserver/Xext/xcmisc.c
cvs rdiff -r1.1.1.1 -r1.1.1.1.4.1 xsrc/xorg/lib/X11/src/ImUtil.c
cvs rdiff -r1.1.1.1 -r1.1.1.1.4.1 xsrc/xorg/lib/Xfont/src/bitmap/bdfread.c
cvs rdiff -r1.1.1.1 -r1.1.1.1.4.1 xsrc/xorg/lib/Xfont/src/fontfile/fontdir.c
cvs rdiff -r1.1.1.1 -r1.1.1.1.4.1 xsrc/xorg/xserver/xorg/Xext/xcmisc.c

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.