-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ## ## Patch description of patch 794d01bfd0bfd8081baf48b7de6ae2eb ## Kind: security Shortdescription.english: Security update for xshared Longdescription.english: Applies to Package: xshared Product(s): Release: 20050127 Obsoletes: none Indications Everyone using GUI applications should update. Contraindications None. Problem description A source code review done by the SuSE Security Team revealed several security problems in libXpm. The bugs are scattered across the whole code and include endless loops, buffer overruns, buffer underruns, code execution via shell meta-chars, path traversal, memory leaks, and integer overflows. These bugs may be used by an attacker to compromise your system through client applications that use libXpm to process data from untrusted sources. The previous security update was to restrictive in checking directory path names. This update resolves these problems. Solution Please install the updates provided at the location noted below. Installation notes This update is provided as an RPM package that can easily be installed onto a running system by using this command: rpm -Fvh xshared.rpm Hsilgne.noitpircsedgnol: Size: 1841 MinYaST1Version: MinYaST2Version: UpdateOnlyInstalled: true Packages: ## ## -----> xshared <----- ## Filename: xshared.rpm Label: X11 shared libs Series: i586 Size: 4136913 1885266 PatchRpmBasedOn: 4.2.0-188 4.2.0-213 4.2.0-267 4.2.0-269 PatchRpmSize: 4136913 1884568 Buildtime: 1106760596 DepAND: DepOR: DepExcl: Flag: Category: RpmGroup: System/Libraries Copyright: X11/MIT AuthorName: AuthorAddress: Version: 4.2.0-270 StartCommand: Obsoletes: Requires: ld-linux.so.2 libICE.so.6 libSM.so.6 libX11.so.6 libXext.so.6 libXmu.so.6 libXmuu.so.1 libXpm.so.4 libXrender.so.1 libXt.so.6 libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libc.so.6(GLIBC_2.1.2) libc.so.6(GLIBC_2.1.3) libc.so.6(GLIBC_2.2) libdl.so.2 libdl.so.2(GLIBC_2.0) libdl.so.2(GLIBC_2.1) libfreetype.so.6 rpmlib(PayloadIsBzip2) <= 3.0.5-1 Provides: xpm XFree86-libs x libICE.so.6 libSM.so.6 libX11.so.6 libXTrap.so.6 libXaw.so.6 libXaw.so.7 libXext.so.6 libXfont.so.1 libXft.so.1 libXi.so.6 libXmu.so.6 libXmuu.so.1 libXp.so.6 libXpm.so.4 libXrandr.so.1 libXrender.so.1 libXt.so.6 libXtst.so.6 libdps.so.1 libdpstk.so.1 libpsres.so.1 libximcp.so libxlcDef.so libxlcUTF8Load.so libxlibi18n.so libxlocale.so libxomGeneric.so libxrx.so.6 Segakcap: -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFB+kFQqE7a6JyACsoRAjRUAJ9vieWK2R7duwmvZXU70Tz/DuBLwgCe Jz6mktjXz+rVjDwt+eGSOkyC4+w= =pi6W -----END PGP SIGNATURE-----