Security Advisory lesstif security update

Advisory: RHSA-2005:004-12
Type: Security Advisory
Severity: Moderate
Issued on: 2005-01-12
Last updated on: 2005-01-12
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0687
CVE-2004-0688
CVE-2004-0914

Details

An updated lesstif package that fixes flaws in the Xpm library is now
available for Red Hat Enterprise Linux 2.1.

LessTif provides libraries which implement the Motif industry standard
graphical user interface.

During a source code audit, Chris Evans discovered several stack overflow
flaws and an integer overflow flaw in the libXpm library used to decode XPM
(X PixMap) images. A vulnerable version of this library was found within
Lesstif. An attacker could create a carefully crafted XPM file which would
cause an application to crash or potentially execute arbitrary code if
opened by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the names CAN-2004-0687,CAN-2004-0688, and
CAN-2004-0914 to these issues.

Users of LessTif are advised to upgrade to this erratum package, which
contains backported security patches to the embedded libXpm library.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
lesstif-0.93.15-4.AS21.4.src.rpm     59665437349ef5bad3f7b373e1dd6001
 
IA-32:
lesstif-0.93.15-4.AS21.4.i386.rpm
File outdated by:  RHSA-2005:473
    9c49c91a9d0668505b1218b60705bd56
lesstif-devel-0.93.15-4.AS21.4.i386.rpm
File outdated by:  RHSA-2005:473
    c9b3a89ad94af645dba780da9e3d86bb
 
IA-64:
lesstif-0.93.15-4.AS21.4.ia64.rpm
File outdated by:  RHSA-2005:473
    9345984ef75ef4878bffe381e6964647
lesstif-devel-0.93.15-4.AS21.4.ia64.rpm
File outdated by:  RHSA-2005:473
    09670ebdb668df8c2281eea87ce42ce8
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
lesstif-0.93.15-4.AS21.4.src.rpm     59665437349ef5bad3f7b373e1dd6001
 
IA-32:
lesstif-0.93.15-4.AS21.4.i386.rpm
File outdated by:  RHSA-2005:473
    9c49c91a9d0668505b1218b60705bd56
lesstif-devel-0.93.15-4.AS21.4.i386.rpm
File outdated by:  RHSA-2005:473
    c9b3a89ad94af645dba780da9e3d86bb
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
lesstif-0.93.15-4.AS21.4.src.rpm     59665437349ef5bad3f7b373e1dd6001
 
IA-32:
lesstif-0.93.15-4.AS21.4.i386.rpm
File outdated by:  RHSA-2005:473
    9c49c91a9d0668505b1218b60705bd56
lesstif-devel-0.93.15-4.AS21.4.i386.rpm
File outdated by:  RHSA-2005:473
    c9b3a89ad94af645dba780da9e3d86bb
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
lesstif-0.93.15-4.AS21.4.src.rpm     59665437349ef5bad3f7b373e1dd6001
 
IA-64:
lesstif-0.93.15-4.AS21.4.ia64.rpm
File outdated by:  RHSA-2005:473
    9345984ef75ef4878bffe381e6964647
lesstif-devel-0.93.15-4.AS21.4.ia64.rpm
File outdated by:  RHSA-2005:473
    09670ebdb668df8c2281eea87ce42ce8
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

135076 - CAN-2004-0687 buffer overflows in libXpm
135079 - CAN-2004-0688 integer overflows in libXpm (CAN-2004-0914)


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/