[ANNOUNCE] libXi 1.6.2.901

2013-05-23 Thread Peter Hutterer
RC1 for libXi 1.6.3 (XI 2.2 support) containing fixes for CVE-2013-1984, CVE-2013-1995, CVE-2013-1998. And a fix to have the correct serial number in GenericEvents. Alan Coopersmith (14): Expand comment on the memory vs. reply ordering in XIGetSelectedEvents() Use _XEatDataWords to avo

[ANNOUNCE] libX11 1.5.99.902 (1.6 RC2)

2013-05-23 Thread Alan Coopersmith
I think it's about time for a second release candidate for Xlib 1.6, don't you? This release is brought to you by the letters C, V, & E, and more numbers than I can count, with a special guest appearance by the letters J́ and j́. Please test & report any issues you find (by May 31 if possible). U

[ANNOUNCE] xf86-video-openchrome 0.3.3

2013-05-23 Thread Xavier Bachelot
Hi, xf86-video-openchrome 0.3.3 has been released. This is a bugfix release. It includes : - Fix integer overflow in libchromeXvMC (CVE-2013-1994). - Various bug fixes and improvements. Get the tarball from http://xorg.freedesktop.org/archive/individual/driver/ xf86-video-openchrome-0.3.3.tar.b

[ANNOUNCE] X.Org Security Advisory: Protocol handling issues in X Window System client libraries

2013-05-23 Thread Alan Coopersmith
X.Org Security Advisory: May 23, 2013 Protocol handling issues in X Window System client libraries Description: Ilja van Sprundel, a security researcher with IOActive, has discovered a large number of issues in the way var