Summary: | [type1] integer overflow in scan_cidfont() | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | xorg | Reporter: | Daniel Stone <daniel> | ||||||
Component: | Server/General | Assignee: | X.Org Security <xorg_security> | ||||||
Status: | RESOLVED FIXED | QA Contact: | |||||||
Severity: | normal | ||||||||
Priority: | high | CC: | alan.coopersmith, dberkholz, matthieu.herrb, sndirsch | ||||||
Version: | git | Keywords: | security | ||||||
Hardware: | x86 (IA32) | ||||||||
OS: | Linux (All) | ||||||||
Whiteboard: | |||||||||
i915 platform: | i915 features: | ||||||||
Attachments: |
|
Description
Daniel Stone
2006-08-25 08:48:50 UTC
*** Bug 8028 has been marked as a duplicate of this bug. *** *** Bug 8006 has been marked as a duplicate of this bug. *** Created attachment 6731 [details] [review] proposed patch for both issues This is CVE-2006-3740 Created attachment 6830 [details] [review] libXfont.diff Patch in attachment #6731 [details] [review] results in a compile failure in module subdir, since INT_MAX/LONG_MAX is already defined in xf86_libc.h, but this one builds fine. Patches committed and advisory released. |
Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.