diff options
| author | Mihai Moldovan <ionic@ionic.de> | 2017-12-15 12:55:17 +0100 |
|---|---|---|
| committer | Mihai Moldovan <ionic@ionic.de> | 2017-12-15 12:55:17 +0100 |
| commit | 1dad092caf01d733990648e6df64cbf964df5143 (patch) | |
| tree | 39de0e643e76754a3e23ca9dd0350b8ba4f76250 /debian/patches/1027-render-check-request-size-before-reading-it-CVE.full.patch | |
| parent | 6d70b9e3c47f27a166f4aacb522c5c1e49092dd9 (diff) | |
| parent | 2b9025f797ee322e21077e100c2ee27c2e7fa0e0 (diff) | |
| download | nx-libs-1dad092caf01d733990648e6df64cbf964df5143.tar.gz nx-libs-1dad092caf01d733990648e6df64cbf964df5143.tar.bz2 nx-libs-1dad092caf01d733990648e6df64cbf964df5143.zip | |
Merge branch '3.6.x'
Diffstat (limited to 'debian/patches/1027-render-check-request-size-before-reading-it-CVE.full.patch')
| -rw-r--r-- | debian/patches/1027-render-check-request-size-before-reading-it-CVE.full.patch | 52 |
1 files changed, 0 insertions, 52 deletions
diff --git a/debian/patches/1027-render-check-request-size-before-reading-it-CVE.full.patch b/debian/patches/1027-render-check-request-size-before-reading-it-CVE.full.patch deleted file mode 100644 index 7e8fe352f..000000000 --- a/debian/patches/1027-render-check-request-size-before-reading-it-CVE.full.patch +++ /dev/null @@ -1,52 +0,0 @@ -From 6c820648ba4be98c94f61516e83f13edf5ed98db Mon Sep 17 00:00:00 2001 -From: Julien Cristau <jcristau@debian.org> -Date: Tue, 28 Oct 2014 10:30:04 +0100 -Subject: [PATCH 27/40] render: check request size before reading it - [CVE-2014-8100 1/2] - -Otherwise we may be reading outside of the client request. - -v2: backport to nx-libs 3.6.x (Mike DePaulo) -v3: port to NXrender.c rather than render.c (Mike DePaulo) -v4: backport v3 to nx-libs 3.5.0.x (Mihai Moldovan) - -Signed-off-by: Julien Cristau <jcristau@debian.org> -Reviewed-by: Alan Coopersmith <alan.coopersmith@oracle.com> -Signed-off-by: Alan Coopersmith <alan.coopersmith@oracle.com> - -Conflicts: - render/render.c ---- - nx-X11/programs/Xserver/render/render.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - ---- a/nx-X11/programs/Xserver/render/render.c -+++ b/nx-X11/programs/Xserver/render/render.c -@@ -283,10 +283,11 @@ ProcRenderQueryVersion (ClientPtr client - register int n; - REQUEST(xRenderQueryVersionReq); - -+ REQUEST_SIZE_MATCH(xRenderQueryVersionReq); -+ - pRenderClient->major_version = stuff->majorVersion; - pRenderClient->minor_version = stuff->minorVersion; - -- REQUEST_SIZE_MATCH(xRenderQueryVersionReq); - rep.type = X_Reply; - rep.length = 0; - rep.sequenceNumber = client->sequence; ---- a/nx-X11/programs/Xserver/hw/nxagent/NXrender.c -+++ b/nx-X11/programs/Xserver/hw/nxagent/NXrender.c -@@ -326,10 +326,11 @@ ProcRenderQueryVersion (ClientPtr client - register int n; - REQUEST(xRenderQueryVersionReq); - -+ REQUEST_SIZE_MATCH(xRenderQueryVersionReq); -+ - pRenderClient->major_version = stuff->majorVersion; - pRenderClient->minor_version = stuff->minorVersion; - -- REQUEST_SIZE_MATCH(xRenderQueryVersionReq); - rep.type = X_Reply; - rep.length = 0; - rep.sequenceNumber = client->sequence; |
