/srv/irclogs.ubuntu.com/2013/10/16/#ubuntu-x.txt

tjaaltonlightdm login screen doesn't seem to switch the display off after awhile09:16
mdeslaurmlankhorst: fyi, I'm preparing xorg-server security updates, and they will collide with stuff in -proposed unfortunately12:37
mdeslaurmlankhorst: I can rebase the stuff in -proposed when I'm done if you'd like12:37
tjaaltonmdeslaur: CVE-2013-4396?12:38
ubottuUse-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure. (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4396)12:38
mdeslaurtjaalton: that and CVE-2013-1056 in our xkb caching patch12:38
ubottu** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided. (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1056)12:38
tjaaltonI uploaded that one yesterday and it got through aiui12:38
mdeslaurtjaalton: for saucy yes, I'm doing the stable releases12:39
tjaaltonah12:39
mdeslaurtjaalton: thanks for saucy btw12:39
tjaaltonyeah I forgot about the stable ones :)12:39
mlankhorstmdeslaur: eep stable releases :)12:40
mdeslaurmlankhorst: sorry for the collision, it's rather unfortunate and a PITA part of the security update process12:40
mlankhorstyeah :/12:41
tjaaltonoh12:42
tjaaltonyeah I had a few oem-priority fixes there..12:43
mdeslaurtjaalton: in raring-proposed?12:43
mdeslaurtjaalton: or the one mlankhorst just uploaded to precise-proposed?12:43
tjaaltonquantal12:44
tjaaltonand the backport12:44
tjaaltonto precise12:44
tjaalton2:1.13.0-0ubuntu6.312:44
mdeslaurtjaalton: if all goes well, I'll be publishing them tomorrow, so we can re-upload to -proposed after that12:45
tjaaltonthis one didn't even get accepted12:47
tjaaltonyet12:47
mdeslaurit depends how long it's going to take me to rebuild half of the backported raring stack into the -security pocket *sigh*12:48
mlankhorstalways fun :P12:51
mlankhorsttoo bad we have to keep changelog history, it would be so much easier without..12:52

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!