[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#401956: libx11-6: contents of .XCompose file are leaked to subprocesses (possibly unprivileged)



forwarded 401956 https://bugs.freedesktop.org/show_bug.cgi?id=8699
tags 401956 + upstream fixed-upstream fixed-in-experimental
thanks

This is upstream bug #8699, fixed in libX11 1.1-RC2 and later with this
commit:
	http://gitweb.freedesktop.org/?p=xorg/lib/libX11.git;a=commitdiff_plain;h=686bb8b35acf6cecae80fe89b2b5853f5816ce19

According to the upstream bug report, it has been assigned
CVE-2006-5397.

I'd have thought this would be severity 'grave', but I'm not about to
override an RM's opinion. :-) I do think the patch should be included in
etch though: it merely deletes one obviously-wrong line.

--Jamey

Attachment: signature.asc
Description: Digital signature


Reply to: