Bug 152804 - CAN-2004-0687,0688,0914 OpenMotif libxpm flaws
CAN-2004-0687,0688,0914 OpenMotif libxpm flaws
Status: CLOSED ERRATA
Product: Fedora Legacy
Classification: Retired
Component: openmotif (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Fedora Legacy Bugs
https://bugzilla.redhat.com/bugzilla/...
1, LEGACY, QA, rh73, rh90
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-10-08 06:53 EDT by Marc Deslauriers
Modified: 2007-04-18 13:22 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2005-05-12 20:54:58 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description David Lawrence 2005-03-30 18:28:03 EST
During a source code audit, Chris Evans discovered several stack
overflow flaws and an integer overflow flaw in the libXpm library used
to decode XPM (X PixMap) images. A vulnerable version of this library
was found within OpenMotif. An attacker could create a carefully crafted
XPM file which would cause an application to crash or potentially
execute arbitrary code if opened by a victim.  The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0687 and CAN-2004-0688 to these issues.

Thomas Woerner discovered that OpenMotif had embedded an old libxpm
library that is vulnerable to these issues.  

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=134631



------- Additional Comments From michal@harddata.com 2004-10-24 08:15:38 ----

Created an attachment (id=895)
patch to fix libXpm problems in openmotif

Here is a patch derived from what is known as XFree86-openbsd.xpm.sec.patch
and redone for opemotif libraries.

As a matter of fact the same patch works, with possibly some small offsets,
for the whole range of openmotif packages across various distributions:

from openmotif-2.2.2-5 (RH7.3) to openmotif-2.2.3-6 (FC3test) and
from openmotif21-2.1.30-1 (RH7.3) to this openmotif21-2.1.30-11(FC3test)

with this note that an equivalent patch is already applied to 
openmotif-2.2.3-6 package while openmotif21-2.1.30-11 is curiously still
lacking it.

Does openmotif21 need its own bug ticket not to be forgotten?  There
is really no point working separately on openmotif and openmotif21 packages.




------- Additional Comments From michal@harddata.com 2004-10-24 08:51:27 ----

If you wonder what "this openmotif21-2.1.30-11" in comment #1 may mean then
these are unfortunate effects of copy-and-waste. :-)



------- Additional Comments From rob.myers@gtri.gatech.edu 2004-11-04 06:53:41 ----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
Here are updated openmotif and openmotif21 packages to QA for fc1:
  
these CAN's should all be fixed:
CAN-2004-0687, CAN-2004-0688 libxpm flaws
should compile under mach
 
changelogs:
openmotif21-2.1.30-8.1.legacy:
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu>  2.1.30-8.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - added BuildRequires: automake, XFree86-devel
 
openmotif-2.2.2-16.1.1.legacy:
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-16.1.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - add BuildPreReq: libtool, XFree86-devel
  
sha1sums:
42fcf946902ab78df8046bb55a0a545e1364db44  openmotif21-2.1.30-8.1.legacy.i386.rpm
822d8a417eac13cc5114878992e75e0b53185b9f  openmotif21-2.1.30-8.1.legacy.src.rpm
e5aae9b8923ac5c325166f13d225976479d21196 
openmotif21-debuginfo-2.1.30-8.1.legacy.i386.rpm
73fc3b7fc8b87708528e6bc042729e4c93b342bb  openmotif-2.2.2-16.1.1.legacy.i386.rpm
11694b1f5e3412afa493e2c3f11299982d62c6de  openmotif-2.2.2-16.1.1.legacy.src.rpm
b218194f9ba949bd228ccfc735162f179bb6813a 
openmotif-debuginfo-2.2.2-16.1.1.legacy.i386.rpm
5024ca0062fd3535a3f661a3b32add58ce653ae0 
openmotif-devel-2.2.2-16.1.1.legacy.i386.rpm
  
files:
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-8.1.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-8.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-debuginfo-2.1.30-8.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-16.1.1.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-16.1.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-debuginfo-2.2.2-16.1.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-devel-2.2.2-16.1.1.legacy.i386.rpm
 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
 
iD8DBQFBil4WtU2XAt1OWnsRAkbAAKDiZ01nytwzvlTXdnncujHfyaNItwCguVLn
ly/yXNuxE4lFIdbN5hpXwYs=
=rWJK
-----END PGP SIGNATURE-----




------- Additional Comments From rob.myers@gtri.gatech.edu 2004-11-04 07:28:08 ----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
Here is an updated openmotif package to QA for rh9:
  
these CAN's should all be fixed:
CAN-2004-0687, CAN-2004-0688 libxpm flaws
should compile under mach
 
NOTE: the openmotif21 src.rpm is the same as the fc1 release
so renamed binary rpms compiled on rh9 are provided for convenience.
 
changelog:
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-14.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - add BuildPreReq: libtool, XFree86-devel
  
sha1sums:
4a86b5261fc345802a7ce5e8a7fc26dddd9a77ed  openmotif-2.2.2-14.1.legacy.i386.rpm
a42392df10d084991dd3146bdd6b3cf648236335  openmotif-2.2.2-14.1.legacy.src.rpm
f34d16b0c0bfb2ae1d9dc90284bfefe6ae489d3f 
openmotif-debuginfo-2.2.2-14.1.legacy.i386.rpm
6af3ada49eadd4a5f1fe0a3d4eb6e65b41849299  openmotif-devel-2.2.2-14.1.legacy.i386.rpm
6a72cf4d248937a5a006452f77eb76cb27829501  rh9-openmotif21-2.1.30-8.1.legacy.i386.rpm
7db593e9484b2e0f24b12e490043ea41fec9c550 
rh9-openmotif21-debuginfo-2.1.30-8.1.legacy.i386.rpm
  
files:
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-14.1.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-14.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-debuginfo-2.2.2-14.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-devel-2.2.2-14.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/rh9-openmotif21-2.1.30-8.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/rh9-openmotif21-debuginfo-2.1.30-8.1.legacy.i386.rpm
 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
 
iD8DBQFBimZstU2XAt1OWnsRAhAvAJ9uWFtniR8cQENXR5EnDdFEIPtGagCdH3fW
dINi6VJJZVeHh8DkWn3LjfM=
=jvYQ
-----END PGP SIGNATURE-----




------- Additional Comments From rob.myers@gtri.gatech.edu 2004-11-04 10:09:13 ----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
Here are updated openmotif packages to QA for rh73:
  
these CAN's should all be fixed:
CAN-2004-0687, CAN-2004-0688 libxpm flaws
should compile under mach
 
NOTES: libMrm.so libUil.so and seem to have disappeared.
i don't know if this is a problem, but beware.
 
changelogs:
 
openmotif21-2.1.30-1.1.legacy:
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu>  2.1.30-1.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - added BuildRequires: automake, XFree86-devel
 
openmotif-2.2.2-5.1.legacy:
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-5.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - added BuildRequires: flex, byacc, XFree86-devel
 
sha1sums:
95c9d771919e099a1b9735de561d9c6d8d644500  openmotif21-2.1.30-1.1.legacy.i386.rpm
a8d8ef3779b902a5812163bc0b11832662af2f2d  openmotif21-2.1.30-1.1.legacy.src.rpm
7d1132f9e9ae86617eafaeca3fdcb1d862b16224  openmotif-2.2.2-5.1.legacy.i386.rpm
5de91571b45fc2971212f71fd0fc8bd747bfbd87  openmotif-2.2.2-5.1.legacy.src.rpm
3e836df93fa38380ccbc220d473b40ddf2c64725  openmotif-devel-2.2.2-5.1.legacy.i386.rpm
  
files:
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-1.1.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-1.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-5.1.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-5.1.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-devel-2.2.2-5.1.legacy.i386.rpm
 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
 
iD8DBQFBiou0tU2XAt1OWnsRAtiFAKCqaU+Uf/xIE7AXm715hpaCYd0u5gCeOkhu
j/mB3hIYiHJbY5NsJfB+8BA=
=mYWq
-----END PGP SIGNATURE-----




------- Additional Comments From michal@harddata.com 2004-11-19 12:47:44 ----

The following showed up as
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136979#c2

"In addition other issues were discovered and given CAN-2004-0914 which
were embargoed until Nov17".

I am afraid that this is all which I know at this moment.



------- Additional Comments From rob.myers@gtri.gatech.edu 2004-12-02 03:39:00 ----

i'm working on respins to include redhat's patch for CAN-2004-0914.



------- Additional Comments From rob.myers@gtri.gatech.edu 2004-12-02 16:20:13 ----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
Here are updated openmotif21 and openmotif packages to QA for rh73, rh9, and fc1:
 
- - switched to redhat's patch for CAN-2004-0687, CAN-2004-0688
- - used redhat's patch for CAN-2004-0914
- - should now build okay in mach
- - rh73 openmotif21 nolonger requires libXmu.so.6, is that a problem?
 
openmotif21 changelogs:
 
rh73:
* Thu Dec 02 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.1.30-1.2.legacy
- - apply patch for CAN-2004-0914 (FL #2143)
- - use redhat's patch for CAN-2004-0687, CAN-2004-0688
- - added BuildRequires: flex, byacc
  
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.1.30-1.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - added BuildRequires: automake, XFree86-devel
 
rh9:
* Wed Dec 01 2004 Rob Myers <rob.myers@gtri.gatech.edu>  2.1.30-8.0.9.2.legacy
- - apply patch for CAN-2004-0914 (FL #2143)
- - use redhat's patch for CAN-2004-0687, CAN-2004-0688
- - added BuildRequires: flex, byacc
  
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu>  2.1.30-8.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - added BuildRequires: automake, XFree86-devel
 
fc1:
* Wed Dec 01 2004 Rob Myers <rob.myers@gtri.gatech.edu>  2.1.30-8.2.legacy
- - apply patch for CAN-2004-0914 (FL #2143)
- - use redhat's patch for CAN-2004-0687, CAN-2004-0688
- - added BuildRequires: flex, byacc
  
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu>  2.1.30-8.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - added BuildRequires: automake, XFree86-devel
 
openmotif changelogs:
 
rh73:
* Thu Dec 02 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-5.2.legacy
- - apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143)
- - use redhat's patch for CAN-2004-0687, CAN-2004-0688
- - add patch to ltmain.sh to link properly
  
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-5.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - added BuildRequires: flex, byacc, XFree86-devel
 
rh9:
* Thu Dec 02 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-14.2.legacy
- - apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143)
- - use redhat's patch for CAN-2004-0687, CAN-2004-0688
  
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-14.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - add BuildPreReq: libtool, XFree86-devel
 
 
fc1:
* Thu Dec 02 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-16.1.2.legacy
- - apply rediff'd version of redhat's patch for CAN-2004-0914 (FL #2143)
- - use redhat's patch for CAN-2004-0687, CAN-2004-0688
  
* Thu Nov 04 2004 Rob Myers <rob.myers@gtri.gatech.edu> 2.2.2-16.1.1.legacy
- - apply patch for CAN-2004-0687, CAN-2004-0688 (FL #2143)
- - add BuildPreReq: libtool, XFree86-devel
 
this file is available at:
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/2143.txt.asc
 
files:
 
rh73:
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-1.2.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-5.2.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-1.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-5.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-devel-2.2.2-5.2.legacy.i386.rpm
 
rh9:
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-8.0.9.2.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-14.2.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-8.0.9.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-debuginfo-2.1.30-8.0.9.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-14.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-debuginfo-2.2.2-14.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-devel-2.2.2-14.2.legacy.i386.rpm
 
fc1:
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-8.2.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-16.1.2.legacy.src.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-2.1.30-8.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif21-debuginfo-2.1.30-8.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-2.2.2-16.1.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-debuginfo-2.2.2-16.1.2.legacy.i386.rpm
http://www.stl.gtri.gatech.edu/rmyers/fedoralegacy/openmotif-devel-2.2.2-16.1.2.legacy.i386.rpm
 
sha1sums:
 
rh73:
3fb9a26ebe31021dfb1a4c5347dc65a620f66a37  openmotif21-2.1.30-1.2.legacy.i386.rpm
d25f9103a63b80aa79b285d3f81124fc54e50917  openmotif21-2.1.30-1.2.legacy.src.rpm
74ef396f1fbf7e96de3ea0b4aad6546d3fc1fd36  openmotif-2.2.2-5.2.legacy.i386.rpm
926c94565b1dce6eb47cf876b54ab8ab83af4e2c  openmotif-2.2.2-5.2.legacy.src.rpm
e9a8a7976b22cc64e3d1efc0d8109fa85e7f5b42  openmotif-devel-2.2.2-5.2.legacy.i386.rpm
 
rh9:
d7313e65d9c7c4d3e2dd32a1c84c3a5360e29d0d  openmotif21-2.1.30-8.0.9.2.legacy.i386.rpm
ffe6d7cf37e5a8dda5b83b840895d39944b1c61c  openmotif21-2.1.30-8.0.9.2.legacy.src.rpm
6b267e5ba94fba8c2700e9491f77186f1727b4e2 
openmotif21-debuginfo-2.1.30-8.0.9.2.legacy.i386.rpm
34619077d7c9dada151226f014f6b2f8a7874d6e  openmotif-2.2.2-14.2.legacy.i386.rpm
5c23bf00634f68c3d479a73780f7f0807462f649  openmotif-2.2.2-14.2.legacy.src.rpm
51838f07624f2b1bdc59cdfa501b0cfda0843cc2 
openmotif-debuginfo-2.2.2-14.2.legacy.i386.rpm
40b232a7ff525e48e6ae9019b795678acb21bafb  openmotif-devel-2.2.2-14.2.legacy.i386.rpm
 
fc1:
6fe05ba5db2b96418a784ea587ce583305c006e3  openmotif21-2.1.30-8.2.legacy.i386.rpm
e12078ad787fffb562317cb09383427705231bf0  openmotif21-2.1.30-8.2.legacy.src.rpm
5fa617bd0b5b689ecee14fb2142019cd20c07d6d 
openmotif21-debuginfo-2.1.30-8.2.legacy.i386.rpm
d2f7a04b201e667d1ac66c2f0400fd6ac604c479  openmotif-2.2.2-16.1.2.legacy.i386.rpm
1c5f58c5af833345fe1d4788d235bff43d663eb2  openmotif-2.2.2-16.1.2.legacy.src.rpm
294f69d8c945424d96035f7b0f243ed14f8161a9 
openmotif-debuginfo-2.2.2-16.1.2.legacy.i386.rpm
a44a7efcfce19badaa2f761dff3d6dddf5e0131c 
openmotif-devel-2.2.2-16.1.2.legacy.i386.rpm
 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
 
iD8DBQFBr80RtU2XAt1OWnsRArzSAKCs+H6jHfTJskzISm537+polcHnYQCg0y35
kdsH+QBc7hyw0aKze3ZWtw4=
=oX/O
-----END PGP SIGNATURE-----




------- Additional Comments From pekkas@netcore.fi 2004-12-15 03:15:28 ----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
                                                                               
                                        
- - Reviewed FC1 in detail:
 * SPEC file changes sane
 * original tarballs intact, integrity ok
 * the patches only have minor re-patch etc. differences
   to ones shipped with RHEL
- - Also reviewed RHL73 and RHL9 quickly.
                                                                               
                                        
+PUBLISH FC1, (RHL73,RHL9)
                                                                               
                                        
d25f9103a63b80aa79b285d3f81124fc54e50917  openmotif21-2.1.30-1.2.legacy.src.rpm
ffe6d7cf37e5a8dda5b83b840895d39944b1c61c  openmotif21-2.1.30-8.0.9.2.legacy.src.rpm
e12078ad787fffb562317cb09383427705231bf0  openmotif21-2.1.30-8.2.legacy.src.rpm
5c23bf00634f68c3d479a73780f7f0807462f649  openmotif-2.2.2-14.2.legacy.src.rpm
1c5f58c5af833345fe1d4788d235bff43d663eb2  openmotif-2.2.2-16.1.2.legacy.src.rpm
926c94565b1dce6eb47cf876b54ab8ab83af4e2c  openmotif-2.2.2-5.2.legacy.src.rpm
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
                                                                               
                                        
iD8DBQFBwDiyGHbTkzxSL7QRAhSmAKChlsdE/CcdTsSTQTTXzETBCswCDACgg8Ke
A+r2w61VuPlzIfjHUlQ2LTY=
=YBgq
-----END PGP SIGNATURE-----




------- Additional Comments From marcdeslauriers@videotron.ca 2005-02-09 16:17:00 ----

Packages were pushed to updates-testing.



------- Additional Comments From rmy@tigress.co.uk 2005-02-10 01:34:54 ----

-----BEGIN PGP SIGNED MESSAGE-----

I've updated to the following RPMs from updates-testing on rh73:

   069006be17df36fb8bdd4f3144922f2a82b3f255  openmotif-2.2.2-5.2.legacy.i386.rpm
   a687cebff8a3bd4083953a127acc4c5aa47abd56 
openmotif-devel-2.2.2-5.2.legacy.i386.rpm
   fdb330d0eb404befeab472a98001c7a3e9a3a285  openmotif21-2.1.30-1.2.legacy.i386.rpm

SHA checksums and signatures are OK.  No errors in installation (except
that I confused myself because I'd forgotten that my yum.conf had
'exclude=kernel openmotif-devel*', so the devel package wasn't updated
at first).

Our applications are linked against openmotif21.  I've tested a variety
of these and everything seems to work as expected.  The only things I
have that require openmotif-2.2.2 are nedit and ddd.  I don't normally
use them, but they seem to run without incident.

+VERIFY rh73
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iQCVAwUBQgtGSB2/joqPEUdFAQF7wAP/cLCjNJwklfBJFtZ0tBaf97oo6qugDTWn
TaQOHTvZystVJG1fLUd9hSGaBp4tyWaj7pszfiIznaX579PGdzBe6cq902/WxzaA
HsYbKHhim7h5sYaPgUHW3FeMfOWKdc/onGapMZPIyUUwl/u1MTo6Yi5ss7XQifs4
/grgwOBuHgE=
=Elbs
-----END PGP SIGNATURE-----




------- Additional Comments From pekkas@netcore.fi 2005-02-21 23:00:29 ----

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
 
QA for RHL9:
 - GPG signature OK
 - rpm-build-compare on the binaries looks sane
 - installs nicely
 - xemacs which is linked against openmotif runs fine
 
+VERIFY RHL9
 
e215ee7469ba2087b03d92754703089fea7d3daf  openmotif21-2.1.30-8.0.9.2.legacy.i386.rpm
685a0ac8194730e6ccd4f56ae375052beca011b8  openmotif-2.2.2-14.2.legacy.i386.rpm
55805c44030bd081907ef461a9d752c16ec66907  openmotif-devel-2.2.2-14.2.legacy.i386.rpm
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
 
iD8DBQFCGvSfGHbTkzxSL7QRAn7LAJ4xWIPPDiCmPZFF5Qc6Wrxoi5PHHgCePCQY
F5Nmz9+nxFBm8NzPQi2lky8=
=ej34
-----END PGP SIGNATURE-----




------- Bug moved to this database by dkl@redhat.com 2005-03-30 18:28 -------

This bug previously known as bug 2143 at https://bugzilla.fedora.us/
https://bugzilla.fedora.us/show_bug.cgi?id=2143
Originally filed under the Fedora Legacy product and Package request component.

Attachments:
patch to fix libXpm problems in openmotif
https://bugzilla.fedora.us/attachment.cgi?action=view&id=895

Unknown priority P2. Setting to default priority "normal".
Unknown platform PC. Setting to default platform "All".
Setting qa contact to the default for this product.
   This bug either had no qa contact or an invalid one.

Comment 1 mschout 2005-05-09 20:07:46 EDT
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

FC1 Verify:

sha1
openmotif-2.2.2-16.1.2.legacy.i386.rpm
1e7c9aa8fa59add13c049193bfcadc6cf9f18613

openmotif-devel-2.2.2-16.1.2.legacy.i386.rpm
14b5b94cad04f7d08e287651be552ff37adb38f8

openmotif21-2.1.30-8.2.legacy.i386.rpm
4b3d11f17b6997670140d6b39086050ea77928bc

dsa sha1 md5 gpg signatures OK

installed all packages without any warnings or errors

xemacs runs fine.

+VERIFY FC1
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (FreeBSD)

iD8DBQFCgEGE+CqvSzp9LOwRAokcAJ4yMEoFnZXhOm6OCK/ZrDtSC1N45QCgn98d
yDQkaBBmfIy+Yl+X6ymM9bQ=
=rPw9
-----END PGP SIGNATURE-----
Comment 2 Marc Deslauriers 2005-05-12 20:54:58 EDT
Released to updates

Note You need to log in before you can comment on or make changes to this bug.