motif-2.3.4-20.el8

エラータID: AXSA:2024-8322:02

Release date: 
Monday, June 17, 2024 - 20:11
Subject: 
motif-2.3.4-20.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The motif packages include the Motif shared libraries needed to run applications which are dynamically linked against Motif, as well as MWM, the Motif Window Manager.

Security Fix(es):

* libXpm: out of bounds read in XpmCreateXpmImageFromBuffer() (CVE-2023-43788)
* libXpm: out of bounds read on XPM with corrupted colormap (CVE-2023-43789)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 8.10 Release Notes linked from the References section.

CVE-2023-43788
A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This flaw allows a local attacker to trigger an out-of-bounds read error and read the contents of memory on the system.
CVE-2023-43789
A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error and read contents of memory on the system.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. motif-2.3.4-20.el8.src.rpm
    MD5: cdea6ae51d35915a9a54f52ea488790e
    SHA-256: ab35b825b2a094b36fb74f173b3d93c7ba39185bb78dcf306ca3d9ecd9305752
    Size: 9.03 MB

Asianux Server 8 for x86_64
  1. motif-2.3.4-20.el8.i686.rpm
    MD5: 86a601daf123c59642d3bd6e7fcf4503
    SHA-256: fbe45be7f8ae3ef89bcd87a3f986ef1250ed76399c6849250160561051336cd3
    Size: 1.53 MB
  2. motif-2.3.4-20.el8.x86_64.rpm
    MD5: 8269260670857ace4857059f5dd9b12b
    SHA-256: 6ce532a9f90344c460e0a10d804e591712e27834461dad69731192b09292fd4b
    Size: 1.45 MB
  3. motif-devel-2.3.4-20.el8.i686.rpm
    MD5: f5f4a4a66c206578aa96eeb8c49c5837
    SHA-256: 2b0ec0a3d0aaa66780ca5b6a0ffd6bd9ac506b8fc5c0085d5d9134243bfa30a5
    Size: 1.31 MB
  4. motif-devel-2.3.4-20.el8.x86_64.rpm
    MD5: aab32724d88cd1863e083b5b0afba6e8
    SHA-256: d033192296acc5c9ba3f93da89488d43c686e6ad6fd4cfadd5664eda8df997a3
    Size: 1.31 MB
  5. motif-static-2.3.4-20.el8.i686.rpm
    MD5: c00c649867f0959a74524fc45f656142
    SHA-256: 65f6e3e3fe82d1f394ffb5d4148f5a1c087bde83c9e0dbf7d70914e867868a23
    Size: 1.67 MB
  6. motif-static-2.3.4-20.el8.x86_64.rpm
    MD5: a7c4c3742bf5beae7ef54de9738256b9
    SHA-256: c4e3779f55fd87d4bc11e640b530a9bf9faa3502ffb6ba11c5a3bc6cf2436477
    Size: 1.53 MB