From owner-cvs-ports@FreeBSD.ORG Thu Mar 11 13:30:48 2004 Return-Path: Delivered-To: cvs-ports@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4C2FF16A4CE; Thu, 11 Mar 2004 13:30:48 -0800 (PST) Received: from postman.arcor.de (postman2.arcor-online.net [151.189.0.152]) by mx1.FreeBSD.org (Postfix) with ESMTP id A235D43D2D; Thu, 11 Mar 2004 13:30:47 -0800 (PST) (envelope-from eikemeier@fillmore-labs.com) Received: from fillmore.dyndns.org (port-212-202-51-138.reverse.qsc.de [212.202.51.138]) (authenticated bits=0)i2BLUiko020792 (version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NO); Thu, 11 Mar 2004 22:30:45 +0100 (MET) Received: from [172.16.0.2] (helo=fillmore-labs.com) by fillmore.dyndns.org with esmtp (Exim 4.30; FreeBSD) id 1B1XlI-000FqT-Tu; Thu, 11 Mar 2004 22:30:40 +0100 Message-ID: <4050DA80.7070604@fillmore-labs.com> Date: Thu, 11 Mar 2004 22:30:40 +0100 From: Oliver Eikemeier Organization: Fillmore Labs GmbH - http://www.fillmore-labs.com/ MIME-Version: 1.0 To: "Jacques A. Vidrine" References: <200403041722.i24HMSLN083120@repoman.freebsd.org> <20040306153749.R55348@blues.jpj.net> <20040306215342.GA91865@madman.celabo.org> In-Reply-To: <20040306215342.GA91865@madman.celabo.org> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit User-Agent: KMail/1.5.9 cc: Trevor Johnson cc: =?UTF-8?B?RGFnLUVybGluZyBTbcO4cmdyYXY=?= cc: cvs-all@FreeBSD.org cc: ports-committers@FreeBSD.org cc: cvs-ports@FreeBSD.org cc: Trevor Johnson Subject: Re: cvs commit: ports/x11/linux-XFree86-libs Makefile distinfo.i386 X-BeenThere: cvs-ports@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: CVS commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 11 Mar 2004 21:30:48 -0000 Jacques A. Vidrine wrote: > On Sat, Mar 06, 2004 at 04:17:23PM -0500, Trevor Johnson wrote: > >>Dag-Erling [iso-8859-1] Sm?rgrav wrote: >> >> >>>Trevor Johnson writes: >>> >>>> Log: >>>> Update to version 4.3.0-2.90.55 due to several security bugs >>>> (discovered by iDefense and David Dawes) in the parsing of font >>>> files and the font.alias file which can give root privileges to >>>> local users. [...] >>> >>>This is pointless as the bug in question only affects the server. >> >>I hadn't noticed that--when I glanced at >>, which >>addresses these bugs, it looked like the problem was in the X libraries, >>not the server. > > [...] > > The bugs *are* in a library (libXfont), but one could only exploit them > for privilege escalation in the server (which has libXfont compiled > internally). > > I added linux-XFree86-libs to the VuXML entry describing this > vulnerability > (http://www.vuxml.org/freebsd/3837f462-5d6b-11d8-80e3-0020ed76ef5a.html) > without thinking too much. Should I remove it? Just a reminder: This port is still listed in the FreeBSD VuXML database. Please take the appropriate action. Thanks Oliver