motif-2.3.4-28.el9

エラータID: AXSA:2024-7932:01

Release date: 
Thursday, May 30, 2024 - 13:41
Subject: 
motif-2.3.4-28.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The motif packages include the Motif shared libraries needed to run applications which are dynamically linked against Motif, as well as MWM, the Motif Window Manager.

Security Fix(es):

* libXpm: out of bounds read in XpmCreateXpmImageFromBuffer() (CVE-2023-43788)
* libXpm: out of bounds read on XPM with corrupted colormap (CVE-2023-43789)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the MIRACLE LINUX 9.4 Release Notes linked from the References section.

CVE-2023-43788
A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This flaw allows a local attacker to trigger an out-of-bounds read error and read the contents of memory on the system.
CVE-2023-43789
A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error and read contents of memory on the system.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. motif-2.3.4-28.el9.src.rpm
    MD5: 11b25256ed908508631d5d64f18017fb
    SHA-256: 36c891b68b5dbf9fd4cf5a1e3c3831b7effcc00cfb75ac0fcc02230f49533abd
    Size: 9.02 MB

Asianux Server 9 for x86_64
  1. motif-2.3.4-28.el9.i686.rpm
    MD5: 5868305ad756e1c38b1e78aa1c4940d7
    SHA-256: 7096289b43889076c0670deae8d877d5b3cd10f581b84ae80336a249ada3f645
    Size: 1.52 MB
  2. motif-2.3.4-28.el9.x86_64.rpm
    MD5: 9eec1c1214e96771c730c52465479233
    SHA-256: 86844a151c35aefb0e935f610fcab24223b0995fda1cec99e7da5ed54e916598
    Size: 1.45 MB
  3. motif-devel-2.3.4-28.el9.i686.rpm
    MD5: 636ef391256f14971faf3ee76743c809
    SHA-256: b7155b7c2ae530d33a0d2448df623760ce63caf4a7299861939f3cfb1fbf1fa9
    Size: 1.28 MB
  4. motif-devel-2.3.4-28.el9.x86_64.rpm
    MD5: 3fc234551c644f106e868284b33c511d
    SHA-256: ab8f4c399fdd4c5e710fe31fa6e82b9a638672bc9ef9b1b9173517a504e51627
    Size: 1.28 MB