Re: Yet another Xpm vulnerability
Matthias Scheler <[email protected]>
| Newsgroups | gmane.comp.xfree86.devel |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Mar 10, 2005 at 06:37:06PM -0500, David Dawes wrote: > How about the attached patch? I just pulled OpenBSD-current's Xpm source into NetBSD. It has fixes for this vulnerability and various other bug fixes from X.org. > What is the mechanism for getting the bad data into the privileged > program to start with? Maybe a web browser? Kind regards -- Matthias Scheler http://scheler.de/~matthias/