Bug 696316

Summary: xorg-x11-server-utils: xrdb regression introduced by the CVE-2011-0465 fix [rhel-5]
Product: Red Hat Enterprise Linux 5 Reporter: Adam Jackson <ajax>
Component: xorg-x11-server-utilsAssignee: Adam Jackson <ajax>
Status: CLOSED ERRATA QA Contact: desktop-bugs <desktop-bugs>
Severity: medium Docs Contact:
Priority: medium    
Version: 5.6CC: ajax, bressers, ejb, gnugv_maintainer, goeran, jlieskov, j.s.peatfield, marco, mjelists, peder.stray, security-response-team, simon.matter, solgato, syeghiay, tis, vdanen
Target Milestone: rcKeywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: public=20110405,reported=20110224,source=vendorsec,impact=moderate,cvss2=7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C,rhel-5/xorg-x11-server-utils=affected,rhel-4/xorg-x11=affected,rhel-6/xorg-x11-server-utils=affected
Fixed In Version: Doc Type: Bug Fix
Doc Text:
A previous advisory, the RHSA-2011:0433 xorg-x11-server-utils security update, applied a backported patch to fix a flaw in the X server resource database utility, xrdb. While this patch resolved the security issue, it also introduced an error in the macro expansion mechanism. Consequent to this, an attempt to run the xrdb utility could fail with the following messages written to standard error: sh: -c: line 0: unexpected EOF while looking for matching `"' sh: -c: line 1: syntax error: unexpected end of file With this update, the underlying source code has been adapted to correct the macro expansion mechanism, and the xrdb utility now works as expected.
Story Points: ---
Clone Of: CVE-2011-0465 Environment:
Last Closed: 2011-04-19 06:43:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 680196, 681589, 681590, 681591, 681592, 681593, 696317, 833998    
Bug Blocks: 696310    

Comment 1 Adam Jackson 2011-04-13 20:21:25 UTC
3256475 build (RHEL-5.6-Z-candidate, /cvs/dist:rpms/xorg-x11-server-utils/RHEL-5:xorg-x11-server-utils-7_1-5_el5_6_2) completed successfully

MODIFIED

Comment 4 Jaromir Hradilek 2011-04-18 15:12:44 UTC
    Technical note added. If any revisions are required, please edit the "Technical Notes" field
    accordingly. All revisions will be proofread by the Engineering Content Services team.
    
    New Contents:
A previous advisory, the RHSA-2011:0433 xorg-x11-server-utils security update, applied a backported patch to fix a flaw in the X server resource database utility, xrdb. While this patch resolved the security issue, it also introduced an error in the macro expansion mechanism. Consequent to this, an attempt to run the xrdb utility could fail with the following messages written to standard error:

    sh: -c: line 0: unexpected EOF while looking for matching `"'
    sh: -c: line 1: syntax error: unexpected end of file 

With this update, the underlying source code has been adapted to correct the macro expansion mechanism, and the xrdb utility now works as expected.

Comment 5 Adam Jackson 2011-04-18 17:33:18 UTC
*** Bug 695603 has been marked as a duplicate of this bug. ***

Comment 6 errata-xmlrpc 2011-04-19 06:43:02 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2011-0454.html