Re: Yet another Xpm vulnerability

2005-03-11 Thread Matthias Scheler
On Thu, Mar 10, 2005 at 06:37:06PM -0500, David Dawes wrote: How about the attached patch? I just pulled OpenBSD-current's Xpm source into NetBSD. It has fixes for this vulnerability and various other bug fixes from X.org. What is the mechanism for getting the bad data into the privileged

Re: Yet another Xpm vulnerability

2005-03-11 Thread David Dawes
On Fri, Mar 11, 2005 at 12:54:47PM +, Matthias Scheler wrote: On Thu, Mar 10, 2005 at 06:37:06PM -0500, David Dawes wrote: How about the attached patch? I just pulled OpenBSD-current's Xpm source into NetBSD. It has fixes for this vulnerability and various other bug fixes from X.org. I