+++ This bug was initially created as a clone of Bug #150036 +++ A potential buffer overflow from the use of unsigned integers has been found in the XPM processing library of xorg. https://bugs.freedesktop.org/show_bug.cgi?id=1920
This should also affect FC2
Adding to FC3Update tracker
setting to moderate severity since only a subset of applications are affected by this, and many of those do not parse untrusted xpm files. Applications like the gimp and others have their own xpm implementations.
Security updates for FC2 and FC3 have been issued: https://www.redhat.com/archives/fedora-announce-list/2005-March/msg00086.html https://www.redhat.com/archives/fedora-announce-list/2005-March/msg00085.html Closing bug.