Bug 138522
| Summary: | CAN-2004-1025 Multiple imlib issues. (CAN-2004-1026) | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Josh Bressers <bressers> |
| Component: | imlib | Assignee: | Matthias Clasen <mclasen> |
| Status: | CLOSED WONTFIX | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 5 | CC: | marius.andreiana, paul |
| Target Milestone: | --- | Keywords: | Reopened, Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | impact=moderate,public=20040916 | ||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2007-12-18 15:27:26 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Josh Bressers
2004-11-09 19:15:46 UTC
Built a package for these Updates released for RH http://www.linuxcompatible.org/RHSA-2004651-01_Updated_imlib_packages_fix_security_vulnerabilities_s38502.html No updates for FC3: http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/i386/ FC4 includes fix. As this is quite old, leaving to Jonathan decision if there will be any updates or just mark WONTFIX for fc3. I mean Matthias, who is the bug owner. The test pixmap from Bug #138516 crashes qiv (an imlib-based image viewer) on FC4 so it appears that Comment #2 is wrong about FC4 including a fix. Whilst FC4 is no longer maintained, I believe FC5 is still vulnerable (I don't have an FC5 box to test this). For FC6 onwards, imlib moved to Extras, where this issue is recorded in Bug #235416. Fix is included in current Fedora imlib packages: * Tue Apr 10 2007 Paul Howarth <paul> 1:1.9.15-2 - add patch for CVE-2004-1025, CVE-2004-1026 (integer/buffer overflows) (#235416) Fedora Core 5 is no longer maintained. Closing this bug. |