Chris Evans has discovered a number of stack overflows and an integer overflow in the X.org libXpm library. It is unknown what all uses this library for xpm processing, so far we have verified that the gimp does use it. This issue currently has no embargo date.
The embargo date for this issue is Sept 15.
Master bug, with patch: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=131121
Fixed in: 4.3.0-69.EL for RHEL-3 4.1.0-62.EL for RHEL-2.1 4.3.0-69 for FC-1 (shares src.rpm with RHEL-3) 6.7.0-8 for FC-2 6.8.1 for FC-3 (once it's avail and built in rawhide) RPM packages being submitted to beehive shortly.
Removing embargo
Has this issue been fixed in FC2,3?
Yes, and released as erratum.