Source-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[xsrc/netbsd-9]: xsrc/external/mit/xorg-server.old/dist/Xi Apply patch, reque...



details:   https://anonhg.NetBSD.org/xsrc/rev/3646884daec2
branches:  netbsd-9
changeset: 10710:3646884daec2
user:      martin <martin%NetBSD.org@localhost>
date:      Tue Apr 27 10:41:36 2021 +0000

description:
Apply patch, requested by mrg in ticket #1257:

        external/mit/xorg-server/dist/Xi/chgfctl.c      (apply patch)
        external/mit/xorg-server.old/dist/Xi/chgfctl.c  (apply patch)

Fix for CVE-2021-3472 (local privilege escalation).

diffstat:

 external/mit/xorg-server.old/dist/Xi/chgfctl.c |  5 ++++-
 1 files changed, 4 insertions(+), 1 deletions(-)

diffs (16 lines):

diff -r 07fb2e22b8d4 -r 3646884daec2 external/mit/xorg-server.old/dist/Xi/chgfctl.c
--- a/external/mit/xorg-server.old/dist/Xi/chgfctl.c    Tue Apr 27 10:37:01 2021 +0000
+++ b/external/mit/xorg-server.old/dist/Xi/chgfctl.c    Tue Apr 27 10:41:36 2021 +0000
@@ -468,8 +468,11 @@
     case StringFeedbackClass:
     {
        char n;
-       xStringFeedbackCtl *f = ((xStringFeedbackCtl *) & stuff[1]);
+        xStringFeedbackCtl *f;
 
+        REQUEST_AT_LEAST_EXTRA_SIZE(xChangeFeedbackControlReq,
+                                    sizeof(xStringFeedbackCtl));
+        f = ((xStringFeedbackCtl *) &stuff[1]);
        if (client->swapped) {
             if (len < bytes_to_int32(sizeof(xStringFeedbackCtl)))
                 return BadLength;



Home | Main Index | Thread Index | Old Index