On 10/17/13 04:34 PM, Alan Coopersmith wrote:
On 10/17/13 04:29 PM, Matt Dew wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi all,
Today was the nominal 1.14.4-rc2 release. I've gotten no
nominations, pull or cherry-pick requests since 1.14.3 was released.
1.14.4 should include the recent CVE fix, once keith pulls it into master.
Okay - it's there now, so I'd like to nominate these two commits to be
cherry-picked into 1.14.4 (I've not had a chance to do this myself to
test them though):
Avoid use-after-free in dix/dixfonts.c: doImageText() [CVE-2013-4396]
http://cgit.freedesktop.org/xorg/xserver/commit/?id=73b2660d7273d175d279d22f8ca0c3932a14ff1c
Allow disabling XFree86-DGA, DRI, VidModeExtension extensions
http://cgit.freedesktop.org/xorg/xserver/commit/?id=5a36cdd91530d27627e39159a89b53f9fbb75280
--
-Alan Coopersmith- [email protected]
Oracle Solaris Engineering - http://blogs.oracle.com/alanc
_______________________________________________
[email protected]: X.Org development
Archives: http://lists.x.org/archives/xorg-devel
Info: http://lists.x.org/mailman/listinfo/xorg-devel