Subject: PR/34050 CVS commit: [pkgsrc-2006Q2] pkgsrc/x11/x11vnc
To: None <salo@NetBSD.org, gnats-admin@netbsd.org, pkgsrc-bugs@netbsd.org,>
From: Lubomir Sedlacik <salo@netbsd.org>
List: pkgsrc-bugs
Date: 07/22/2006 16:30:02
The following reply was made to PR pkg/34050; it has been noted by GNATS.

From: Lubomir Sedlacik <salo@netbsd.org>
To: gnats-bugs@NetBSD.org
Cc: 
Subject: PR/34050 CVS commit: [pkgsrc-2006Q2] pkgsrc/x11/x11vnc
Date: Sat, 22 Jul 2006 16:26:27 +0000 (UTC)

 Module Name:	pkgsrc
 Committed By:	salo
 Date:		Sat Jul 22 16:26:27 UTC 2006
 
 Modified Files:
 	pkgsrc/x11/x11vnc [pkgsrc-2006Q2]: Makefile PLIST distinfo
 
 Log Message:
 Pullup ticket 1745 - requested by bad
 security update for x11vnc
 
 Revisions pulled up:
 - pkgsrc/x11/x11vnc/Makefile			1.4
 - pkgsrc/x11/x11vnc/PLIST			1.2
 - pkgsrc/x11/x11vnc/distinfo			1.3
 
    Module Name:		pkgsrc
    Committed By:	salo
    Date:		Sat Jul 22 12:19:47 UTC 2006
 
    Modified Files:
    	pkgsrc/x11/x11vnc: Makefile PLIST distinfo
 
    Log Message:
    Security update to version 0.8.2
 
    Changes:
 
    Security fix for CVE-2006-2450, remote authentication bypass
    in libvncserver.
 
    Notified by the upstream maintainer, Karl Runge via PR pkg/34050
 
    New in the 0.8.2 x11vnc release:
    ================================
 
      Support for full mouse and keyboard input into the Linux
              console framebuffer /dev/fb0 in -rawfb mode
              (i.e. non-X11) by using the Linux üinput" driver.
 
              This enables, for example, viewing and interacting
              with Qt-embedded/Qtopia-Core apps on Linux-based
              handhelds, etc.
 
              Options:   -rawfb cons, -pipeinput UINPUT More info:
              http://www.karlrunge.com/x11vnc/#faq-qt-embedded
 
      Extension of the display option: -display WAIT:<disp-or-cmd>
              to delay x11vnc's opening of the X display
              until a VNC client connects (useful built-in:
              -display WAIT:cmd=FINDDISPLAY, to find a user's
              display and Xauthority data).
 
      Options -grabkbd and -grabptr have x11vnc try to grab
              the X display when VNC clients are connected to
              prevent a (non-malicious) user at the physical X
              display from performing keyboard or mouse input.
              E.g. remote help-desk support.
 
     miscellaneous new features and changes:
 
      -allowedcmds option to fine-tune which external commands
              may be run by x11vnc, rather than shutting
              them all off with -nocmds.
      -env VAR=VALUE convenience option to avoid the need of
              setting environment variables before starting
              x11vnc.
      -allinput option to enable libvncserver handleEventsEagerly
              parameter (not clear it yields an improvement).
      -rawfb rand  fun/testing option using /dev/urandom as a fb.
      -license, -copying, -warranty option.
 
    New in the 0.8.1 x11vnc release:
    ================================
 
      Improved support for webcams and TV tuners with video4linux
              /dev/video: see the "-rawfb video" and "-pipeinput VID"
              options. (the latter gives a simple keyboard control
              of a TV tuner; see also the -freqtab option for stations).
 
      FBPM support for hardware that provides framebuffer power
              management (it needs to be disabled when vnc clients
              are connected).
 
      The -usepw option will require x11vnc to use a password of
              some sort or otherwise exit immediately.  Put it in
              your ~/.x11vncrc so you don't forget.
 
      The command "x11vnc -storepasswd" will prompt for a password
              without echoing and save it in ~/.vnc/passwd
 
      The X CLIPBOARD selection is managed in addition to the
                    X PRIMARY selection.
 
     miscellaneous new features and changes:
 
      Convenience option for accessing the Linux console: -rawfb cons
              etc. (requires /dev/fb0 to be working).
 
      clipboard/cut-text input can now be managed on a per-client
              basis.
 
      -capslock and -skip_lockkeys options can help make CapsLock work
              better.
 
      The Xdummy wrapper script is included in the source tree.
 
      A mode "-gone popup" as been added.
 
      -24to32 option to avoid 24bpp problems.
 
      -xinerama is on by default.
 
 
 To generate a diff of this commit:
 cvs rdiff -r1.3 -r1.3.4.1 pkgsrc/x11/x11vnc/Makefile
 cvs rdiff -r1.1.1.1 -r1.1.1.1.8.1 pkgsrc/x11/x11vnc/PLIST
 cvs rdiff -r1.2 -r1.2.4.1 pkgsrc/x11/x11vnc/distinfo
 
 Please note that diffs are not public domain; they are subject to the
 copyright notices on the relevant files.