[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#145048: marked as done (libxt6: XtAppInitialize() SEGVs if an app-defaults file #includes itself)



Your message dated Sat, 25 May 2013 22:17:33 +0000
with message-id <E1UgMmL-0004tY-0E@franck.debian.org>
and subject line Bug#145048: fixed in libx11 2:1.3.3-4+squeeze1
has caused the Debian Bug report #145048,
regarding libxt6: XtAppInitialize() SEGVs if an app-defaults file #includes itself
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
145048: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=145048
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: xterm
Version: 4.1.0-16
Severity: normal

If I include "XTerm" in /etc/X11/app-defaults/XTerm itself, xterm
segfaults (reproduceable on two different machines):

# echo "#include \"XTerm\"" >> /etc/X11/app-defaults/XTerm && xterm
Speicherzugriffsfehler
#



-- System Information
Debian Release: 3.0
Architecture: i386
Kernel: Linux hosi.de 2.4.18 #2 Sam Mär 23 17:58:00 CET 2002 i686
Locale: LANG=de_DE@euro, LC_CTYPE=de_DE@euro

Versions of packages xterm depends on:
ii  debconf                  1.0.32          Debian configuration management sy
ii  libc6                    2.2.5-4         GNU C Library: Shared libraries an
ii  libfreetype6             2.0.9-1         FreeType 2 font engine, shared lib
ii  libncurses5              5.2.20020112a-7 Shared libraries for terminal hand
ii  libxaw7                  4.1.0-16        X Athena widget set library
ii  xlibs                    4.1.0-16        X Window System client libraries



--- End Message ---
--- Begin Message ---
Source: libx11
Source-Version: 2:1.3.3-4+squeeze1

We believe that the bug you reported is fixed in the latest version of
libx11, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 145048@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Julien Cristau <jcristau@debian.org> (supplier of updated libx11 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Tue, 21 May 2013 22:26:20 +0200
Source: libx11
Binary: libx11-6 libx11-6-udeb libx11-data libx11-6-dbg libx11-dev libx11-xcb1 libx11-xcb1-dbg libx11-xcb-dev
Architecture: source all amd64
Version: 2:1.3.3-4+squeeze1
Distribution: squeeze-security
Urgency: high
Maintainer: Debian X Strike Force <debian-x@lists.debian.org>
Changed-By: Julien Cristau <jcristau@debian.org>
Description: 
 libx11-6   - X11 client-side library
 libx11-6-dbg - X11 client-side library (debug package)
 libx11-6-udeb - X11 client-side library (udeb)
 libx11-data - X11 client-side library
 libx11-dev - X11 client-side library (development headers)
 libx11-xcb-dev - Xlib/XCB interface library (development headers)
 libx11-xcb1 - Xlib/XCB interface library
 libx11-xcb1-dbg - Xlib/XCB interface library (debug package)
Closes: 145048
Changes: 
 libx11 (2:1.3.3-4+squeeze1) squeeze-security; urgency=high
 .
   * CVE-2013-1981: integer overflows calculating memory needs for replies
   * CVE-2013-1997: buffer overflows due to not validating length or offset
     values in replies
   * CVE-2013-2004: unbounded recursion parsing user-specified files
     (closes: #145048)
Checksums-Sha1: 
 e67c8b9f9ba76e5fe448ef78dfa557ef27cd3ba6 2245 libx11_1.3.3-4+squeeze1.dsc
 d900f8aa985376683690df9d36a864220dc48390 2899688 libx11_1.3.3.orig.tar.gz
 0d14889937e40a0ac96280412a8584df6eb8cc15 155452 libx11_1.3.3-4+squeeze1.diff.gz
 8d7e9f795dfb514d100863c8ec0f63d8d1c9081a 184280 libx11-data_1.3.3-4+squeeze1_all.deb
 31c51cbedaa71b7f90c1f9cca29bcd902c286e19 846850 libx11-6_1.3.3-4+squeeze1_amd64.deb
 844140cbd50e97efc78ee120f23c7ef7ad09523e 760224 libx11-6-udeb_1.3.3-4+squeeze1_amd64.udeb
 a91e159792d0ab571772d9c99687408d2efe14de 2785712 libx11-6-dbg_1.3.3-4+squeeze1_amd64.deb
 9ff8e285a3ca16ce5508d5af1b42531b19547d5e 3515624 libx11-dev_1.3.3-4+squeeze1_amd64.deb
 d426f4d4b2d91cd6a05a973202dadd28e7298730 90340 libx11-xcb1_1.3.3-4+squeeze1_amd64.deb
 d4369895e4e801bb4edaf93da5ef5f48cc6f4ddf 104310 libx11-xcb1-dbg_1.3.3-4+squeeze1_amd64.deb
 44a512849ad51411ea701ddbc128b0e30bfbbecc 92438 libx11-xcb-dev_1.3.3-4+squeeze1_amd64.deb
Checksums-Sha256: 
 fb6ca75967de4263aad60b8ae2812ea759fb908152678af41f06a4f10c4da053 2245 libx11_1.3.3-4+squeeze1.dsc
 91274846aebcc9b1867d051c87833ef8f1a1ebe372b675373dd2a744360a8734 2899688 libx11_1.3.3.orig.tar.gz
 22f6fefd5ed57b7c3fc57d64c922b575a160102bd1212a554120f650ae923d0c 155452 libx11_1.3.3-4+squeeze1.diff.gz
 bb5e83fb3d86d7e8158c31f9c47cfa966fb9f875028252514d676c7e2fbeeb8c 184280 libx11-data_1.3.3-4+squeeze1_all.deb
 624c1682ea99251fb0a1f46528d5cf2738fd3c4f594f86a6f781c89d50bdca28 846850 libx11-6_1.3.3-4+squeeze1_amd64.deb
 41d049446812740282865111d5e6e4cc3da18d03c86c95a9b7cd74ab9d1f2926 760224 libx11-6-udeb_1.3.3-4+squeeze1_amd64.udeb
 b4aade70d9d703374a24945e6a054c8537d9facb9c62b9d180869726c7f03783 2785712 libx11-6-dbg_1.3.3-4+squeeze1_amd64.deb
 d0242e5738ef7af7f9f340e070a68bcb7033c9c06c36ff30715272784d33bd32 3515624 libx11-dev_1.3.3-4+squeeze1_amd64.deb
 1d2820930fac026737a7520790a7b6154693389a510f5e5fcae18b44a28edca1 90340 libx11-xcb1_1.3.3-4+squeeze1_amd64.deb
 4a986a3eec27bb418cdf81d94d5d2209b08bbcdb585f7c44a93d5295e651d0b3 104310 libx11-xcb1-dbg_1.3.3-4+squeeze1_amd64.deb
 4556e04560d98c65c3c38d68958604df7c5dd048c9725ac4197912512b31e281 92438 libx11-xcb-dev_1.3.3-4+squeeze1_amd64.deb
Files: 
 6ab949497d816b1d450e0e1f2a15da08 2245 x11 optional libx11_1.3.3-4+squeeze1.dsc
 f5669fa5843e54cb4cc7ebf8f7cc741e 2899688 x11 optional libx11_1.3.3.orig.tar.gz
 926ad66aea7bdf9ed48e835742116d4e 155452 x11 optional libx11_1.3.3-4+squeeze1.diff.gz
 5fc7f93bdb449846ea32eb04fdc175f2 184280 x11 optional libx11-data_1.3.3-4+squeeze1_all.deb
 7830afc549ae6d75a7a548b4ce568453 846850 libs optional libx11-6_1.3.3-4+squeeze1_amd64.deb
 4cf7ab94f757b4d935ac0bcc55278e72 760224 debian-installer optional libx11-6-udeb_1.3.3-4+squeeze1_amd64.udeb
 0a5c453468c811869180f36287697a35 2785712 debug extra libx11-6-dbg_1.3.3-4+squeeze1_amd64.deb
 0bcbf24df37af9e5c3bc16aa8bd0ae47 3515624 libdevel optional libx11-dev_1.3.3-4+squeeze1_amd64.deb
 99f114343c43b00968b9b3ba597cf712 90340 libs optional libx11-xcb1_1.3.3-4+squeeze1_amd64.deb
 6332f7cb7b8c475a003cfbbb797ef89f 104310 debug extra libx11-xcb1-dbg_1.3.3-4+squeeze1_amd64.deb
 e717e3c4152fb4f228577783d058de36 92438 libdevel optional libx11-xcb-dev_1.3.3-4+squeeze1_amd64.deb
Package-Type: udeb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJRm+tFAAoJEDEBgAUJBeQMMMYP/RIqpG1ITIi+CspCEzIJncP8
APAxob1gEvlCt+q22pmhrK6hpBnsrtYNt6nXAEIjTuEWwNdWpA3AfpfbkeY8jcCd
xG9uExYsoeAX2P1zdrz+q+3zq4bfAz3H9emZHpgbZ/HlgUMPDYI4A1KGOJWL/ixz
6OMURtnjJt75zI8ud4D54wtu27QFAUzO9ijZ5fOH/xFKMSJB+glAericO7766XsJ
uYZmy9iTHeGXi20iXKPm0625mo0ScJ2jFSLn054UJRgdxOAVU5vfVvZkNOlIsqmh
3hTtSO97Ice/DVHXYbrLrUTc5jliecZn5DH04dbAVJeL5gX99XDFEW7tistd7aEy
ZoMc5eiFbQj4DfxC/BBSfVVtGXEI4BYhEtPJbF64s7LJRiD7NNgYT2M3ryrIiPAy
L6DWEdi3H0lBjWrTu+T9WWMX4OyzZH6igQfrGsx620gQxJJix+UR4QWjs5yKDwDZ
xuO712Wt/iVCIhnDvZWtEahaedE6897VwViWE1xdyLDLNsMrRGjIamOGQ9VHMJFV
4juugMiE+Vvma6cuV/fxsw2on46sXkzghUSXjMMtNTgPrN0w5JdpfaYaWgywJu82
ex6hBv/8s4THxVs85rdIvVN9UvfYESW5bPYXyHLAdQxlFAFEt//yK8CfsLzs5Glj
eZTDAy99dDSgeUOFaynH
=O4nd
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: