Bug#646156: pu: package xorg-server/2:1.7.7-14

2011-11-27 Thread vladz
On Sat, Oct 29, 2011 at 03:03:49PM -0400, Michael Gilbert wrote: On Sat, Oct 29, 2011 at 13:38:47 -0400, Michael Gilbert wrote: On Fri, Oct 21, 2011 at 3:12 PM, Julien Cristau wrote: I wonder if at least this one should be treated with a real urgency? On the surface its an info disclosure

Bug#646156: pu: package xorg-server/2:1.7.7-14

2011-10-30 Thread Adam D. Barratt
tag 646156 + pending thanks On Sat, 2011-10-29 at 15:25 +0100, Adam D. Barratt wrote: tag 646156 + confirmed squeeze thanks On Fri, 2011-10-21 at 21:12 +0200, Julien Cristau wrote: there were a couple of CVEs for X recently, that Moritz suggested we fixed through p-u. And an input fix

Bug#646156: pu: package xorg-server/2:1.7.7-14

2011-10-29 Thread Adam D. Barratt
tag 646156 + confirmed squeeze thanks On Fri, 2011-10-21 at 21:12 +0200, Julien Cristau wrote: there were a couple of CVEs for X recently, that Moritz suggested we fixed through p-u. And an input fix to use 64bit arithmetic to avoid overflows with high resolution devices, that's been sitting

Processed: Re: Bug#646156: pu: package xorg-server/2:1.7.7-14

2011-10-29 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tag 646156 + confirmed squeeze Bug #646156 [release.debian.org] pu: package xorg-server/2:1.7.7-14 Added tag(s) squeeze and confirmed. thanks Stopping processing here. Please contact me if you need assistance. -- 646156:

Bug#646156: pu: package xorg-server/2:1.7.7-14

2011-10-29 Thread Michael Gilbert
On Fri, Oct 21, 2011 at 3:12 PM, Julien Cristau wrote: +commit 03ff880e8bf20cdecaf27f03391ea31545ecc22c +Author: Matthieu Herrb matthieu.he...@laas.fr +Date:   Mon Oct 17 22:27:35 2011 +0200 + +    Fix CVE-2011-4029: File permission change vulnerability. + +    Use fchmod() to change

Bug#646156: pu: package xorg-server/2:1.7.7-14

2011-10-29 Thread Julien Cristau
On Sat, Oct 29, 2011 at 13:38:47 -0400, Michael Gilbert wrote: On Fri, Oct 21, 2011 at 3:12 PM, Julien Cristau wrote: +commit 03ff880e8bf20cdecaf27f03391ea31545ecc22c +Author: Matthieu Herrb matthieu.he...@laas.fr +Date:   Mon Oct 17 22:27:35 2011 +0200 + +    Fix CVE-2011-4029: File

Bug#646156: pu: package xorg-server/2:1.7.7-14

2011-10-29 Thread Michael Gilbert
On Sat, Oct 29, 2011 at 2:58 PM, Julien Cristau wrote: On Sat, Oct 29, 2011 at 13:38:47 -0400, Michael Gilbert wrote: On Fri, Oct 21, 2011 at 3:12 PM, Julien Cristau wrote: +commit 03ff880e8bf20cdecaf27f03391ea31545ecc22c +Author: Matthieu Herrb matthieu.he...@laas.fr +Date:   Mon Oct 17

Bug#646156: pu: package xorg-server/2:1.7.7-14

2011-10-21 Thread Julien Cristau
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: pu Hi, there were a couple of CVEs for X recently, that Moritz suggested we fixed through p-u. And an input fix to use 64bit arithmetic to avoid overflows with high resolution devices, that's