Bug 127552

Summary: Buffer Overflow Bug in OpenMotif 2.2.3
Product: [openSUSE] SUSE LINUX 10.0 Reporter: Andreas Petersik <petersik>
Component: BasesystemAssignee: Andreas Schwab <schwab>
Status: RESOLVED WONTFIX QA Contact: E-mail List <qa-bugs>
Severity: Critical    
Priority: P5 - None CC: security-team
Version: Final   
Target Milestone: ---   
Hardware: x86   
OS: All   
Whiteboard:
Found By: Customer Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Attachments: xpms.zip
motif bug known for years- with solution

Description Andreas Petersik 2005-10-11 13:48:39 UTC
When an OpenMotif application tries to open an XPM Bitmap, the application is
terminated due to a buffer overflow.
The OpenMotif version 2.2.4 from www.opengroup.org/openmotif fixes the problem.
Comment 1 Thomas Biege 2005-10-11 13:54:08 UTC

*** This bug has been marked as a duplicate of 83496 ***
Comment 2 Thomas Biege 2005-10-11 15:38:56 UTC
Looks like the only affected version of openmotif is the one from SL10.

Andreas P., can you please attach the xpm image that triggers the bug?
Comment 4 Thomas Biege 2005-10-12 13:11:07 UTC
sorry, forgot to attach the image files.
Comment 5 Andreas Schwab 2005-10-13 10:04:22 UTC
Where is the test case? 
Comment 6 Thomas Biege 2005-10-13 10:43:08 UTC
Andreas P,
can you attach a code snippet that is used to open the XPM files please.
Thanks.
Comment 7 Forgotten User PZ4wA53Xsq 2005-10-19 11:55:39 UTC
Created attachment 54750 [details]
motif bug known for years- with solution

openmotif 2.2.3 and 2.2.4 have a bug in TextF.C
multibyte characters trigger errors from which
the program can not recover. Applying the patch
for TextF.C fixes the problems, in addition problems
with pixmap loading are gone. In openmotif 2.4 and later
this bug will be fixed
Comment 8 Marcus Meissner 2006-03-29 14:24:00 UTC
i think #c7 provides the needed information.
Comment 9 Andreas Schwab 2006-04-11 09:30:03 UTC
This has nothing to do with the bug.
Comment 10 Thomas Biege 2006-06-01 04:08:44 UTC
ping
Comment 11 Thomas Biege 2006-10-13 11:32:18 UTC
Andreas P. can you help us here?
Comment 12 Andreas Jaeger 2007-02-01 13:12:40 UTC
No reaction for 3 months.  What should happen?
Comment 13 Andreas Schwab 2007-02-01 13:24:32 UTC
Can't do anything without a test case.