From owner-freebsd-security Sun Jun 1 23:58:10 1997 Return-Path: Received: (from root@localhost) by hub.freebsd.org (8.8.5/8.8.5) id XAA02878 for security-outgoing; Sun, 1 Jun 1997 23:58:10 -0700 (PDT) Received: from rf900.physics.usyd.edu.au (rf900.physics.usyd.edu.au [129.78.129.109]) by hub.freebsd.org (8.8.5/8.8.5) with ESMTP id XAA02873 for ; Sun, 1 Jun 1997 23:58:06 -0700 (PDT) Received: (from dawes@localhost) by rf900.physics.usyd.edu.au (8.8.5/8.8.2) id QAA28958; Mon, 2 Jun 1997 16:57:35 +1000 (EST) Message-ID: <19970602165734.49045@rf900.physics.usyd.edu.au> Date: Mon, 2 Jun 1997 16:57:34 +1000 From: David Dawes To: Eivind Eklund Cc: rich@rich.isdn.bcm.tmc.edu, security@FreeBSD.ORG Subject: Re: X libraries References: <199705301538.RAA08714@bitbox.follo.net> <199705302341.SAA08966@rich.isdn.bcm.tmc.edu> <199706020619.IAA18628@bitbox.follo.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Mailer: Mutt 0.69 In-Reply-To: <199706020619.IAA18628@bitbox.follo.net>; from Eivind Eklund on Mon, Jun 02, 1997 at 08:19:32AM +0200 Sender: owner-security@FreeBSD.ORG X-Loop: FreeBSD.org Precedence: bulk On Mon, Jun 02, 1997 at 08:19:32AM +0200, Eivind Eklund wrote: >> >> |Hopefully XFree will provide replacement libraries soon; if not, I'll >> |try to do it, but I'm not presently equipped to compile new libraries >> |for all FreeBSD versions. (The XFree liason is Cc:'ed - can you >> |comment on this, Rich?) >> >> I guess I've missed other discussions about the bug. >> We can include the patch for freebsd untill XFree86 >> picks it up if that's the consensus. > >I don't know how quickly we feel we need to react - if XFree 3.3 come >in two weeks (as the rumors say), then we can depend on that and >still have as quick response as most commercial vendors. However, Red >Hat has already provided a binary patch for _their_ systems. XFree86 3.3 was just finalised, and will be released this week. >Depends on how people feel; I'm not quite certain how I we should >react to bugs in bundled software. > >> Have you talked to anyone else with XFree86 about it? > >No. However, it is all over bugtraq, so I guess they should know. You shouldn't make such assumptions. As it turns out we did know about it. But, if everyone had assumed that we wouldn't have known about it in time to do anything about it for this release. David