Re: [PATCH:libXxf86vm] Discard correct length for old-format replies in XF86VidModeGetGamma

2015-01-05 Thread Alan Coopersmith
Ignore this - this version isn't quite right either, since it doesn't switch between the two reply sizes. -alan- On 01/ 5/15 11:42 PM, Alan Coopersmith wrote: Regression introduced in libXxf86vm 1.1.3 / commit 284a88e21fc05a63466 Unlikely to be hit in practice since it requires out-of-r

[PATCH:libXxf86vm] Discard correct length for old-format replies in XF86VidModeGetGamma

2015-01-05 Thread Alan Coopersmith
Regression introduced in libXxf86vm 1.1.3 / commit 284a88e21fc05a63466 Unlikely to be hit in practice since it requires out-of-range privsize or malloc failure while talking to a server using the XFree86 3.x version of the protocol. Found by Oracle Parfait 1.5.1: Error: Uninitialised memory (CWE