Source-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: xsrc/external/mit/xrdb/dist



Module Name:    xsrc
Committed By:   mrg
Date:           Wed Apr  6 02:06:19 UTC 2011

Update of /cvsroot/xsrc/external/mit/xrdb/dist
In directory ivanova.netbsd.org:/tmp/cvs-serv12644

Log Message:
initial import of xrdb-1.0.9.  fixes CVE-2011-0465: 

By crafting hostnames with shell escape characters, arbitrary commands
can be executed in a root environment when a display manager reads in
the resource database via xrdb.

These specially crafted hostnames can occur in two environments:

  * Hosts that set their hostname via DHCP
  * Hosts that allow remote logins via xdmcp


i will send pullups for netbsd-5, and see what netbsd-5 xfree and
netbsd-4 need as well.

Status:

Vendor Tag:     xorg
Release Tags:   xrdb-1-0-9
                
U xsrc/external/mit/xrdb/dist/AUTHORS
U xsrc/external/mit/xrdb/dist/Makefile.am
U xsrc/external/mit/xrdb/dist/depcomp
U xsrc/external/mit/xrdb/dist/missing
U xsrc/external/mit/xrdb/dist/config.sub
U xsrc/external/mit/xrdb/dist/COPYING
U xsrc/external/mit/xrdb/dist/README
C xsrc/external/mit/xrdb/dist/xrdb.c
U xsrc/external/mit/xrdb/dist/configure.ac
U xsrc/external/mit/xrdb/dist/INSTALL
U xsrc/external/mit/xrdb/dist/config.h.in
U xsrc/external/mit/xrdb/dist/configure
U xsrc/external/mit/xrdb/dist/ChangeLog
U xsrc/external/mit/xrdb/dist/install-sh
U xsrc/external/mit/xrdb/dist/aclocal.m4
U xsrc/external/mit/xrdb/dist/Makefile.in
U xsrc/external/mit/xrdb/dist/config.guess
U xsrc/external/mit/xrdb/dist/man/Makefile.am
U xsrc/external/mit/xrdb/dist/man/xrdb.man
U xsrc/external/mit/xrdb/dist/man/Makefile.in

1 conflicts created by this import.
Use the following command to help the merge:

        cvs checkout -jxorg:yesterday -jxorg xsrc/external/mit/xrdb/dist



Home | Main Index | Thread Index | Old Index