2007
xfs (1:1.0.1-7) stable-security; urgency=high
* Security upload. * Fix several vulnerabilities (CVE-2007-4568): The QueryXBitmaps and QueryXExtents protocol requests suffer from lack of validation of their 'length' parameters. Maliciously crafted requests can either cause two different problems with both requests: + An integer overflow in the computation of the size of a dynamic buffer can lead to a heap overflow in the build_range() function. + An arbitrary number of bytes on the heap can be swapped by the swap_char2b() function. * See upstream security advisory: http://lists.freedesktop.org/archives/xorg-announce/2007-October/000416.html
-- Julien Cristau <jcristau@debian.org> Tue, 02 Oct 2007 20:21:48 +0200
xfs (1:1.0.1-6) stable-security; urgency=high
* Security upload. * Fix race condition in the xfs init script (CVE-2007-3103).
-- Julien Cristau <jcristau@debian.org> Sat, 28 Jul 2007 19:28:37 +0200
2006
xfs (1:1.0.1-5) unstable; urgency=low
* Move config file back to /etc/X11/fs where it belongs. Thanks to Mike
Brodbelt, Otavio Salvador, and Margarita Manterola. Thanks to
Andreas Metzler for the patch. (closes: #362492)
* Run dh_install with --list-missing
* Add quilt to build-depends
-- David Nusinow <dnusinow@debian.org> Mon, 8 May 2006 00:29:18 -0400
xfs (1:1.0.1-4) unstable; urgency=low
* Upload to unstable
-- David Nusinow <dnusinow@debian.org> Tue, 4 Apr 2006 18:44:42 -0400
xfs (1:1.0.1-3) experimental; urgency=low
* Provide the correct copyright info
-- David Nusinow <dnusinow@debian.org> Wed, 8 Mar 2006 00:42:29 -0500
xfs (1:1.0.1-2) experimental; urgency=low
* Provide all our old packaging infrastrcture that I totally forgot. Thanks
Rasmus Bøg Hansen. (closes: #355762)
+ Update config.cpp patch for our font locations and remove the cache
options because they're not working
-- David Nusinow <dnusinow@debian.org> Tue, 7 Mar 2006 22:14:35 -0500
xfs (1:1.0.1-1) experimental; urgency=low
* First modular upload to Debian
* Port patches from trunk
+ general/003b_xfs_fixes.diff
+ debian/906_debian_xfs.diff
-- David Nusinow <dnusinow@debian.org> Sun, 5 Mar 2006 20:12:51 -0500