[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
This bug was fixed in the package xorg-server - 2:1.11.4-0ubuntu10.5 --- xorg-server (2:1.11.4-0ubuntu10.5) precise-security; urgency=low * SECURITY UPDATE: do not use input device names in logging format strings (LP: #996250): - debian/patches/509_log-format-fix.patch: backported upstream changes. - CVE-2012-2118 -- Steve Beattie sbeat...@ubuntu.com Mon, 09 Jul 2012 15:24:55 -0700 ** Changed in: xorg-server (Ubuntu Precise) Status: In Progress = Fix Released -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
** Branch linked: lp:ubuntu/precise-security/xorg-server -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
After experimenting with a reproducer from Kees Cook, I was unable to reproduce this issue with the X server in either oneiric or natty. I'm going to close the tasks for those releases. Thanks! ** Changed in: xorg-server (Ubuntu Natty) Status: In Progress = Won't Fix ** Changed in: xorg-server (Ubuntu Oneiric) Status: In Progress = Won't Fix -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
** Changed in: xorg-server (Ubuntu Natty) Assignee: (unassigned) = Steve Beattie (sbeattie) ** Changed in: xorg-server (Ubuntu Oneiric) Assignee: (unassigned) = Steve Beattie (sbeattie) ** Changed in: xorg-server (Ubuntu Precise) Assignee: (unassigned) = Steve Beattie (sbeattie) ** Changed in: xorg-server (Ubuntu Natty) Status: Confirmed = In Progress ** Changed in: xorg-server (Ubuntu Oneiric) Status: Confirmed = In Progress ** Changed in: xorg-server (Ubuntu Precise) Status: Confirmed = In Progress -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
** Changed in: xorg-server (Ubuntu Quantal) Status: Confirmed = Fix Released -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
Rebase onto latest precise xorg-server. Tested on amd64, evil HID no longer crashes xorg. ** Patch added: xorg-server_1.11.4-0ubuntu10.3.debdiff https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+attachment/3209315/+files/xorg-server_1.11.4-0ubuntu10.3.debdiff -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
Bug was introduced in xserver 1.10. ** Changed in: xorg-server (Ubuntu Lucid) Status: Confirmed = Invalid -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
** Changed in: xorg-server (Ubuntu Lucid) Status: New = Confirmed ** Changed in: xorg-server (Ubuntu Lucid) Importance: Undecided = Low ** Changed in: xorg-server (Ubuntu Natty) Status: New = Confirmed ** Changed in: xorg-server (Ubuntu Natty) Importance: Undecided = Low ** Changed in: xorg-server (Ubuntu Oneiric) Status: New = Confirmed ** Changed in: xorg-server (Ubuntu Oneiric) Importance: Undecided = Low ** Changed in: xorg-server (Ubuntu Precise) Status: New = Confirmed ** Changed in: xorg-server (Ubuntu Precise) Importance: Undecided = Low ** Changed in: xorg-server (Ubuntu Quantal) Status: New = Confirmed ** Changed in: xorg-server (Ubuntu Quantal) Importance: Undecided = Low ** Changed in: xorg-server (Ubuntu Hardy) Status: New = Won't Fix -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
** Patch added: xorg-server_1.11.4-0ubuntu10.2.debdiff https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+attachment/3136013/+files/xorg-server_1.11.4-0ubuntu10.2.debdiff ** Also affects: xorg-server (Ubuntu Lucid) Importance: Undecided Status: New ** Also affects: xorg-server (Ubuntu Natty) Importance: Undecided Status: New ** Also affects: xorg-server (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: xorg-server (Ubuntu Quantal) Importance: Undecided Status: New ** Also affects: xorg-server (Ubuntu Hardy) Importance: Undecided Status: New ** Also affects: xorg-server (Ubuntu Oneiric) Importance: Undecided Status: New ** Visibility changed to: Public -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp
[Ubuntu-x-swat] [Bug 996250] Re: input device names used in logging format strings
** Tags added: patch -- You received this bug notification because you are a member of Ubuntu-X, which is subscribed to xorg-server in Ubuntu. https://bugs.launchpad.net/bugs/996250 Title: input device names used in logging format strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/xorg-server/+bug/996250/+subscriptions ___ Mailing list: https://launchpad.net/~ubuntu-x-swat Post to : ubuntu-x-swat@lists.launchpad.net Unsubscribe : https://launchpad.net/~ubuntu-x-swat More help : https://help.launchpad.net/ListHelp