On 10/17/13 04:34 PM, Alan Coopersmith wrote:
On 10/17/13 04:29 PM, Matt Dew wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi all,
  Today was the nominal 1.14.4-rc2 release.  I've gotten no
nominations, pull or cherry-pick requests since 1.14.3 was released.

1.14.4 should include the recent CVE fix, once keith pulls it into master.

Okay - it's there now, so I'd like to nominate these two commits to be
cherry-picked into 1.14.4 (I've not had a chance to do this myself to
test them though):

Avoid use-after-free in dix/dixfonts.c: doImageText() [CVE-2013-4396]
http://cgit.freedesktop.org/xorg/xserver/commit/?id=73b2660d7273d175d279d22f8ca0c3932a14ff1c

Allow disabling XFree86-DGA, DRI, VidModeExtension extensions
http://cgit.freedesktop.org/xorg/xserver/commit/?id=5a36cdd91530d27627e39159a89b53f9fbb75280

--
        -Alan Coopersmith-              [email protected]
         Oracle Solaris Engineering - http://blogs.oracle.com/alanc
_______________________________________________
[email protected]: X.Org development
Archives: http://lists.x.org/archives/xorg-devel
Info: http://lists.x.org/mailman/listinfo/xorg-devel

Reply via email to