Bug 152923
| Summary: | xloadimage vulnerabilities CAN-2005-0638, CAN-2005-3178 | ||
|---|---|---|---|
| Product: | [Retired] Fedora Legacy | Reporter: | John Dalbec <jpdalbec> |
| Component: | xloadimage | Assignee: | Fedora Legacy Bugs <bugs> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | bugzilla.redhat, deisenst, donjr, pekkas |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | rh73, rh90, 1, 2 | ||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2006-05-13 00:52:02 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
David Lawrence
2005-03-30 23:32:25 UTC
CAN-2005-0605 affects openmotif as well; see https://rhn.redhat.com/errata/RHSA-2005-412.html Since this is a bug for package "xloadimage", I think the only CVE that is relevant to this bug report should be CAN-2005-0639. The two other CVE's are for different packages. I've cleaned up the summary line. Shouldn't this be CVE-2005-0638 and not CVE-2005-0639? CVE-2005-0639 applies to xli only, CVE-2005-0638 to xli and xloadimage. Add CAN-2005-3178 to this as well. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I have created the following patches: rh73: ea00930909d08331e7e0bc6746d4fa66fc5761c4 http://lance.maner.org/xloadimage-4.1-21.1.legacy.src.rpm rh9: e25e1758fd6c1f9e6ecb04f82a13509e17cc80cd http://lance.maner.org/xloadimage-4.1-27.1.legacy.src.rpm fc1: d879c4532942277d592ec46d78fdb6756b1f901a http://lance.maner.org/xloadimage-4.1-29.1.legacy.src.rpm fc2: c455fa54f8aa73d7f28d579f7c3cdeac56180047 http://lance.maner.org/xloadimage-4.1-30.1.legacy.src.rpm -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFEGffJpxMPKJzn2lIRAqlcAKC9BG3UGBZ7QshwoHGxAL8dlo6VXgCgqcUF x08bU25aHANnSe6vIdS78as= =0AQL -----END PGP SIGNATURE----- The FC2 package probably needs to be redone, you probably didn't notice that the latest FC2 package is "xloadimage-4.1-34.FC2.src.rpm" ? The patches were OK. There was unnecessary spec file rename in RHL73 package, but for consistency, that shouldn't be a problem. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Whoops. Thanks Pekka. Correct version below. fc2: 345a3702ec4f770edc37094d2e8d984a06102b1a http://lance.maner.org/xloadimage-4.1-34.1.legacy.src.rpm -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFEGrM1pxMPKJzn2lIRAgAXAJoDRLQHqkrLdgBsyZgTzUCMUhbKtwCfTW6V PSrbi1o6tNmi7p+SFnAVYME= =rXxn -----END PGP SIGNATURE----- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 QA w/ rpm-build-compare.sh: - source integrity good - spec file changes minimal (RHL73 was just a rename) - patches are identical to upstream NOTE: I'm not sure if the FC2 package may need to be renamed, but that can be done at build time if needed. +PUBLISH RHL73, RHL9, FC1, FC2 ea00930909d08331e7e0bc6746d4fa66fc5761c4 xloadimage-4.1-21.1.legacy.src.rpm e25e1758fd6c1f9e6ecb04f82a13509e17cc80cd xloadimage-4.1-27.1.legacy.src.rpm d879c4532942277d592ec46d78fdb6756b1f901a xloadimage-4.1-29.1.legacy.src.rpm 345a3702ec4f770edc37094d2e8d984a06102b1a xloadimage-4.1-34.1.legacy.src.rpm -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFEGrjpGHbTkzxSL7QRAr3wAKChLmhOxPtMkfLyVUDvzaVYgLKgsQCgtnDk oAAz3egrRRtNU2x8qV7yKXY= =BY5P -----END PGP SIGNATURE----- Packages were pushed to updates-testing Timeout over. Packages were released to updates. |