Debian Bug report logs - #308783
libxpm4: new s_popen() function is insecure garbage

version graph

Package: libxpm4; Maintainer for libxpm4 is Debian X Strike Force <debian-x@lists.debian.org>; Source for libxpm4 is src:libxpm (PTS, buildd, popcon).

Reported by: Matej Vela <vela@debian.org>

Date: Thu, 12 May 2005 11:03:05 UTC

Owned by: Branden Robinson <branden@debian.org>

Severity: grave

Tags: fixed-upstream, security

Found in version 4.3.0.dfsg.1-12

Fixed in version xfree86/4.3.0.dfsg.1-14

Done: fabbione@fabbione.net (Fabio M. Di Nitto)

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Matej Vela <vela@debian.org>:
New Bug report received and forwarded. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>. (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Matej Vela <vela@debian.org>
To: submit@bugs.debian.org
Subject: libxpm4: problems with s_popen (CAN-2004-0914)
Date: Thu, 12 May 2005 12:59:04 +0200
Package: libxpm4
Version: 4.3.0.dfsg.1-12
Severity: grave
Justification: may allow access to the accounts of users who use the package

The CAN-2004-0914 patch introduced a s_popen() function as a safe
replacement for popen().  Instead of invoking a shell, it splits
arguments on whitespace and passes the command directly to execvp(3).
However, it doesn't handle quoting or redirection, so code like

  WrFFrI.c:339:       snprintf(buf, sizeof(buf), "gzip -q > \"%s\"", filename);
  WrFFrI.c:340:       if (!(mdata->stream.file = s_popen(buf, "w")))

results in a ">" argument and superfluous quotes:

  execve("/bin/gzip", ["gzip", ">", "\"foo.gz\""], [/* 19 vars */])

This completely breaks the transparent compression and decompression.

Furthermore, since gzip processes all arguments regardless of errors, an
attacker can use filenames with whitespace to compress arbitrary files:
(xpmtest taken from <https://bugs.freedesktop.org/show_bug.cgi?id=1920>)

  # ./xpmtest crab.xpm 'fnord -v /etc/hosts.deny fnord.gz'
  w=28, h=28, cpp=2, cols=6, vmask=00000000, hotspot=0,0
  gzip: >: No such file or directory
  gzip: "fnord: No such file or directory
  /etc/hosts.deny:       -50.0% -- replaced with /etc/hosts.deny.gz
  gzip: fnord.gz": No such file or directory

The above would effectively disable TCP wrappers.  The -r option can be
used to compress whole directory trees.

s_popen() also has issues with error handling, signals, and runaway
child processes.  All of this has been fixed in X11R6.8.2, though I
don't think they're aware of the security implications (patches at
<http://ftp.x.org/pub/X11R6.8.1/patches/> are still vulnerable).

Thanks,

Matej



Tags added: security Request was from Matej Vela <vela@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Changed Bug title. Request was from Branden Robinson <branden@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Bug 308783 cloned as bug 309143. Request was from Branden Robinson <branden@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Message sent on to Matej Vela <vela@debian.org>:
Bug#308783. (full text, mbox, link).


Message #14 received at 308783-submitter@bugs.debian.org (full text, mbox, reply):

From: Branden Robinson <branden@debian.org>
To: 308783-submitter@bugs.debian.org, control@bugs.debian.org
Subject: Re: Bug#308783: libxpm4: problems with s_popen (CAN-2004-0914)
Date: Sat, 14 May 2005 16:20:47 -0500
[Message part 1 (text/plain, inline)]
# This doesn't actually have much to do with CAN-2004-0914.
retitle 308783 libxpm4: new s_popen() function is insecure garbage
# X.Org X11R6.8.2 has code that fixes this.
tag 30783 fixed-upstream
# David Nusinow is working on this.
owne 308783 David Nusinow <dnusinow@debian.org>
# XFree86 4.1.0 in woody, which ships the Xpm library in a different
# package, has this flaw as well.
clone 308783 -1
retitle -1 xlibs: libxpm4's new s_popen() function is insecure garbage
reassign -1 xlibs
tag -1 woody
thanks

Matej,

If there is a security problem here, and I suppose there is given the
failure of s_open() to properly scrutinize its arguments as you indicate,
then please contact MITRE and ask for a CAN number, and/or ask
freedesktop.org to do so.

-- 
G. Branden Robinson                |       If atheism is a religion, then
Debian GNU/Linux                   |       health is a disease.
branden@debian.org                 |       -- Clark Adams
http://people.debian.org/~branden/ |
[signature.asc (application/pgp-signature, inline)]

Tags added: fixed-upstream Request was from Branden Robinson <branden@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Owner recorded as David Nusinow <dnusinow@debian.org>. Request was from Branden Robinson <branden@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Branden Robinson <branden@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>. (full text, mbox, link).


Message #23 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Branden Robinson <branden@debian.org>
To: Debian Security Team <security@debian.org>
Cc: 308783@bugs.debian.org, 309143@bugs.debian.org
Subject: RFC: Bug#308783: libxpm4: problems with s_popen (CAN-2004-0914)
Date: Thu, 19 May 2005 00:01:26 -0500
[Message part 1 (text/plain, inline)]
Could I get a second opinion (or more than one) from you guys as to whether
this is actually an exploitable security problem?

I have been talking to Steve Langasek in his capacity as a Release Manager
about this, and he says if it's not an exploitable problem, then it's not
really a security issue, not really RC, and therefore not deserving of
excepting from the freeze.

Note that I cloned this bug for stable as #309143, and whatever conclusions
are reached here will probably map to that as well.

I asked Matej to follow-up with more information about this, and to contact
freedesktop.org and/or MITRE for a CAN allocation, but haven't heard
anything back from him yet.

If there's any more information I can provide, please let me know.

----- Forwarded message from Matej Vela <vela@debian.org> -----

From: Matej Vela <vela@debian.org>
To: submit@bugs.debian.org
Subject: Bug#308783: libxpm4: problems with s_popen (CAN-2004-0914)
Date: Thu, 12 May 2005 12:59:04 +0200
Message-ID: <20050512105900.GP14871@irb.hr>
List-Id: <debian-x.lists.debian.org>
X-Mailing-List: <debian-x@lists.debian.org> archive/latest/26382
User-Agent: Mutt/1.5.6+20040907i
X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE 
	autolearn=no version=2.60-bugs.debian.org_2005_01_02

Package: libxpm4
Version: 4.3.0.dfsg.1-12
Severity: grave
Justification: may allow access to the accounts of users who use the package

The CAN-2004-0914 patch introduced a s_popen() function as a safe
replacement for popen().  Instead of invoking a shell, it splits
arguments on whitespace and passes the command directly to execvp(3).
However, it doesn't handle quoting or redirection, so code like

  WrFFrI.c:339:       snprintf(buf, sizeof(buf), "gzip -q > \"%s\"", filename);
  WrFFrI.c:340:       if (!(mdata->stream.file = s_popen(buf, "w")))

results in a ">" argument and superfluous quotes:

  execve("/bin/gzip", ["gzip", ">", "\"foo.gz\""], [/* 19 vars */])

This completely breaks the transparent compression and decompression.

Furthermore, since gzip processes all arguments regardless of errors, an
attacker can use filenames with whitespace to compress arbitrary files:
(xpmtest taken from <https://bugs.freedesktop.org/show_bug.cgi?id=1920>)

  # ./xpmtest crab.xpm 'fnord -v /etc/hosts.deny fnord.gz'
  w=28, h=28, cpp=2, cols=6, vmask=00000000, hotspot=0,0
  gzip: >: No such file or directory
  gzip: "fnord: No such file or directory
  /etc/hosts.deny:       -50.0% -- replaced with /etc/hosts.deny.gz
  gzip: fnord.gz": No such file or directory

The above would effectively disable TCP wrappers.  The -r option can be
used to compress whole directory trees.

s_popen() also has issues with error handling, signals, and runaway
child processes.  All of this has been fixed in X11R6.8.2, though I
don't think they're aware of the security implications (patches at
<http://ftp.x.org/pub/X11R6.8.1/patches/> are still vulnerable).

Thanks,

Matej


-- 
To UNSUBSCRIBE, email to debian-x-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


----- End forwarded message -----

-- 
G. Branden Robinson                |     Communism is just one step on the
Debian GNU/Linux                   |     long road from capitalism to
branden@debian.org                 |     capitalism.
http://people.debian.org/~branden/ |     -- Russian saying
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Larry Doolittle <ldoolitt-dated-1117221356.5c9575@recycle.lbl.gov>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>. (full text, mbox, link).


Message #28 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Larry Doolittle <ldoolitt@recycle.lbl.gov>
To: 308783@bugs.debian.org
Subject: Re: new s_popen() function is insecure garbage
Date: Sun, 22 May 2005 12:15:55 -0700
[Message part 1 (text/plain, inline)]
Branden Robinson asked:
> Could I get a second opinion (or more than one) from you guys as to
> whether this is actually an exploitable security problem?

I can't answer this in the affirmative, but then I only spent
about 15 minutes looking for a way to exploit it.  I note that
apt-rdepends finds 9043 packages that depend on libxpm4, so
the opportunities are immense.  It's probably easier to fix
the problem then scrutinize 9043 packages for plausible cases
of uncontrolled input of xpm file names.

Matej's assessment is:
> This completely breaks the transparent compression and decompression.

Which I agree with.  The options for addressing this bug are:

1. Do nothing, almost guaranteeing an exploit will be found.

2. Write a real fix, instead of the stupid s_popen thing.

I might play around with option 2.  There are two strategies
that make technical sense:
  a. skip the sprintf/parsing step, and go directly to
        execlp("uncompress","-c",filename);
  b. put the uncompress/unzip code (zlib calls) inline
Where (a) involves less coding and makes fewer changes to the
build/depends process, but (b) is probably more robust at runtime.
The compression and decompression methods become distinct code paths.

Is someone from the Debian X Strike Force already working on this?

      - Larry
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Daniel Stone <daniel@fooishbar.org>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>. (full text, mbox, link).


Message #33 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Daniel Stone <daniel@fooishbar.org>
To: Larry Doolittle <ldoolitt-dated-1117221356.5c9575@recycle.lbl.gov>, 308783@bugs.debian.org
Subject: Re: Bug#308783: new s_popen() function is insecure garbage
Date: Mon, 23 May 2005 11:32:19 +1000
[Message part 1 (text/plain, inline)]
On Sun, May 22, 2005 at 12:15:55PM -0700, Larry Doolittle wrote:
> 2. Write a real fix, instead of the stupid s_popen thing.
> 
> I might play around with option 2.  There are two strategies
> that make technical sense:

Why would you do this when there's already a version upstream that fixes
this?  I don't like the idea of having yet another Xpm 'security fix'
variant out there.
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Larry Doolittle <ldoolitt@recycle.lbl.gov>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>. (full text, mbox, link).


Message #38 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Larry Doolittle <ldoolitt@recycle.lbl.gov>
To: Daniel Stone <daniel@fooishbar.org>
Cc: 308783@bugs.debian.org
Subject: Re: Bug#308783: new s_popen() function is insecure garbage
Date: Sun, 22 May 2005 19:56:44 -0700
[Message part 1 (text/plain, inline)]
Daniel et al. -

On Mon, May 23, 2005 at 11:32:19AM +1000, Daniel Stone wrote:
> > I might play around with option 2.  There are two strategies
> > that make technical sense:
> 
> Why would you do this when there's already a version upstream that fixes
> this?  I don't like the idea of having yet another Xpm 'security fix'
> variant out there.

OK, so I was slow finding the proper upstream fix.
Now that I found it within
  http://ftp.x.org/pub/X11R6.8.2/patches/X11R6.8.1-to-X11R6.8.2.patch.gz
I gave it a quick review (it matches my strategy (a)).

So, let me rephrase the question:

Has Matej and someone from the Debian X Strike Force reviewed
and/or started to test the X11R6.8.2 patch to 
  xc/extras/Xpm/lib/RdFToI.c
  xc/extras/Xpm/lib/WrFFrI.c
and maybe
  xc/extras/Xpm/lib/XpmI.h
?

    - Larry
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Larry Doolittle <ldoolitt@recycle.lbl.gov>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>. (full text, mbox, link).


Message #43 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Larry Doolittle <ldoolitt@recycle.lbl.gov>
To: Thomas Biege <thomas@suse.de>
Cc: 308783@bugs.debian.org
Subject: RdFToI.c
Date: Mon, 23 May 2005 11:20:52 -0700
[Message part 1 (text/plain, inline)]
Thomas -

I just read your patch to RdFToI.c titled
October 2004, source code review by Thomas Biege <thomas@suse.de>
where you replaced calls to popen with the new routine xpmPipeThrough().
That is a big improvement, and debian needs to incorporate that
improvement in the upcoming sarge release.  (see
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=308783
)

I noticed you changed the semantics of compressed file detection.
The old code looked like
	if ((len > 2) && !strcmp(".Z", filename + (len - 2))) {
	    ...
	} else if ((len > 3) && !strcmp(".gz", filename + (len - 3))) {
	    ...
	}
so the filename passed in to OpenReadFile() is expected to have
the .Z or .gz already added to it.

The new code looks something like
	int fd = open(filename, O_RDONLY);
	const char* ext = NULL;
	if ( fd >= 0 ) {
		ext = strrchr(filename, '.');
	} else {
		char *compressfile = (char *) XpmMalloc(strlen(filename) + 4);
		strcpy(compressfile, filename);
		strcpy(compressfile + len, ext = ".Z")
		fd = open(compressfile, O_RDONLY);
		if ( fd < 0 ) {
			strcpy(compressfile + len, ext = ".gz");
			fd = open(compressfile, O_RDONLY);
			   ...
		}
	}
so the filename passed in to OpenReadFile() is _not_ expected to
have the .Z or .gz already added to it, the code will add the
suffix to the bare .xpm name.

Is this important?  Do you know what code depends on which kind
of behavior?  This change is not particularly relevant to the actual
bug fix, and my first impression is that it should not go in to
sarge.

      - Larry
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Larry Doolittle <ldoolitt@recycle.lbl.gov>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>. (full text, mbox, link).


Message #48 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Larry Doolittle <ldoolitt@recycle.lbl.gov>
To: Larry Doolittle <ldoolitt@recycle.lbl.gov>
Cc: Thomas Biege <thomas@suse.de>, 308783@bugs.debian.org
Subject: Re: RdFToI.c
Date: Mon, 23 May 2005 11:46:43 -0700
[Message part 1 (text/plain, inline)]
On Mon, May 23, 2005 at 11:20:52AM -0700, Larry Doolittle wrote:
> [chop]
> I noticed you changed the semantics of compressed file detection.

Sorry for the brainless chatter.  I jumped to conclusions after
reading the patch, not looking at or testing the final code.

Both versions of the code (before and after your fix) handle
both modes (with or without the .Z or .gz supplied) just fine.

       - Larry
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Larry Doolittle <ldoolitt@recycle.lbl.gov>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>. (full text, mbox, link).


Message #53 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Larry Doolittle <ldoolitt@recycle.lbl.gov>
To: 308783@bugs.debian.org
Subject: patch
Date: Mon, 23 May 2005 12:57:54 -0700
[Message part 1 (text/plain, inline)]
See attached.
In case of too many mail/BTS/web gateways, I posted a backup copy at
http://recycle.lbl.gov/~ldoolitt/087a_SECURITY_libXpm_vulnerabilities.diff

When I say "tested" I mean tested in isolation.
My attempts to fully test the debian build process
have so far failed, for (I think) unrelated reasons.
apt-src and I are not friends yet.

    - Larry
[087a_SECURITY_libXpm_vulnerabilities.diff (text/plain, attachment)]
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Thomas Biege <thomas@suse.de>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, David Nusinow <dnusinow@debian.org>. (full text, mbox, link).


Message #58 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Thomas Biege <thomas@suse.de>
To: Larry Doolittle <ldoolitt@recycle.lbl.gov>
Cc: 308783@bugs.debian.org
Subject: Re: RdFToI.c
Date: Tue, 24 May 2005 10:21:54 +0200
On Mon, May 23, 2005 at 11:46:43AM -0700, Larry Doolittle wrote:
> On Mon, May 23, 2005 at 11:20:52AM -0700, Larry Doolittle wrote:
> > [chop]
> > I noticed you changed the semantics of compressed file detection.
> 
> Sorry for the brainless chatter.  I jumped to conclusions after
> reading the patch, not looking at or testing the final code.
> 
> Both versions of the code (before and after your fix) handle
> both modes (with or without the .Z or .gz supplied) just fine.

Ok. No problem. :)


>        - Larry



-- 
Bye,
     Thomas
-- 
 Thomas Biege <thomas@suse.de>, SUSE LINUX, Security Support & Auditing
-- 
                  Imagine there's no countries, It isnt hard to do,
                  Nothing to kill or die for, No religion too, ...
                                -- John Lennon (Imagine Lyrics)



Owner changed from David Nusinow <dnusinow@debian.org> to Branden Robinson <branden@debian.org>. Request was from Branden Robinson <branden@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Tags added: pending Request was from Branden Robinson <branden@debian.org> to control@bugs.debian.org. (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, Branden Robinson <branden@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to 308783@bugs.debian.org:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, Branden Robinson <branden@debian.org>. (full text, mbox, link).


Message #67 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Branden Robinson <branden@debian.org>
To: 308783@bugs.debian.org
Cc: debian-release@lists.debian.org, fabbione@fabbione.net
Subject: status of fix for RC bug #308783 (libxpm4 s_popen() function)
Date: Tue, 31 May 2005 02:49:21 -0500
[Message part 1 (text/plain, inline)]
I've tested an libxpm4 package built from the xfree86 SVN trunk[1].

Reading and writing of uncompressed, ncompressed, and gzipped xpm files
appears to work fine.

To test this, I created an image (attached) using xpaint, and saved it as
"test.xpm", "test.xpm.gz", and "test.xpm.Z".  As far as I can tell from
reviewing xpaint's source code, it relies on the Xpm library to handle
compression and decompression.

I then ran the following compound command from the shell prompt:
$ for F in test.xpm*; do cxpm "$F" && echo cxpm test of $F PASSED; sxpm \
  "$F" && echo sxpm test of $F PASSED; done

I got the following results:
cxpm test of test.xpm PASSED
sxpm test of test.xpm PASSED
cxpm test of test.xpm.Z PASSED
sxpm test of test.xpm.Z PASSED
cxpm test of test.xpm.gz PASSED
sxpm test of test.xpm.gz PASSED

(Remember that pressing "q" in sxpm's window gracefully exits the program.)

The next thing to do is to run my upgrade/downgrade/install/purge test
battery in some chroots, and then I will hand this off to Fabio for (knock
wood) the final release of xfree86 for sarge.

[1] http://necrotic.deadbeast.net/svn/xfree86/trunk/

-- 
G. Branden Robinson                |     I'm not going to waste my precious
Debian GNU/Linux                   |     flash memory with Perl when I can
branden@debian.org                 |     do so much more with it.
http://people.debian.org/~branden/ |     -- Joey Hess
[test.xpm (image/x-xpixmap, attachment)]
[test.xpm.gz (application/octet-stream, attachment)]
[test.xpm.Z (text/plain, attachment)]
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Branden Robinson <branden@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>. (full text, mbox, link).


Message #72 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Branden Robinson <branden@debian.org>
To: 308783@bugs.debian.org, fabbione@fabbione.net, debian-release@lists.debian.org
Subject: xfree86 SVN trunk ready for branch merge and release
Date: Tue, 31 May 2005 03:47:10 -0500
[Message part 1 (text/plain, inline)]
I've tested all the xfree86 packages built from the current SVN trunk in my
chroots.

Upgrade/downgrade and install/purge tests pass.

Fabio, build at will and upload unless the RM team says not to.  Remember
to ask the RMs to force -14 into sarge.

Now I've got to pack for Brazil.  :)

-- 
G. Branden Robinson                |      When dogma enters the brain, all
Debian GNU/Linux                   |      intellectual activity ceases.
branden@debian.org                 |      -- Robert Anton Wilson
http://people.debian.org/~branden/ |
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian X Strike Force <debian-x@lists.debian.org>, Branden Robinson <branden@debian.org>:
Bug#308783; Package libxpm4. (full text, mbox, link).


Acknowledgement sent to Steve Langasek <vorlon@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian X Strike Force <debian-x@lists.debian.org>, Branden Robinson <branden@debian.org>. (full text, mbox, link).


Message #77 received at 308783@bugs.debian.org (full text, mbox, reply):

From: Steve Langasek <vorlon@debian.org>
To: Branden Robinson <branden@debian.org>, 308783@bugs.debian.org
Cc: fabbione@fabbione.net, debian-release@lists.debian.org
Subject: Re: Bug#308783: xfree86 SVN trunk ready for branch merge and release
Date: Tue, 31 May 2005 05:08:55 -0700
[Message part 1 (text/plain, inline)]
On Tue, May 31, 2005 at 03:47:10AM -0500, Branden Robinson wrote:
> I've tested all the xfree86 packages built from the current SVN trunk in my
> chroots.

> Upgrade/downgrade and install/purge tests pass.

> Fabio, build at will and upload unless the RM team says not to.  Remember
> to ask the RMs to force -14 into sarge.

As previously noted on IRC, please upload -14 directly as soon as you have
a chance to do so. 

Thanks,
-- 
Steve Langasek
postmodern programmer
[signature.asc (application/pgp-signature, inline)]

Reply sent to fabbione@fabbione.net (Fabio M. Di Nitto):
You have taken responsibility. (full text, mbox, link).


Notification sent to Matej Vela <vela@debian.org>:
Bug acknowledged by developer. (full text, mbox, link).


Message #82 received at 308783-close@bugs.debian.org (full text, mbox, reply):

From: fabbione@fabbione.net (Fabio M. Di Nitto)
To: 308783-close@bugs.debian.org
Subject: Bug#308783: fixed in xfree86 4.3.0.dfsg.1-14
Date: Wed, 01 Jun 2005 03:47:57 -0400
Source: xfree86
Source-Version: 4.3.0.dfsg.1-14

We believe that the bug you reported is fixed in the latest version of
xfree86, which is due to be installed in the Debian FTP archive:

lbxproxy_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/lbxproxy_4.3.0.dfsg.1-14_i386.deb
libdps-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libdps-dev_4.3.0.dfsg.1-14_i386.deb
libdps1-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libdps1-dbg_4.3.0.dfsg.1-14_i386.deb
libdps1_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libdps1_4.3.0.dfsg.1-14_i386.deb
libice-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libice-dev_4.3.0.dfsg.1-14_i386.deb
libice6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libice6-dbg_4.3.0.dfsg.1-14_i386.deb
libice6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libice6_4.3.0.dfsg.1-14_i386.deb
libsm-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libsm-dev_4.3.0.dfsg.1-14_i386.deb
libsm6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libsm6-dbg_4.3.0.dfsg.1-14_i386.deb
libsm6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libsm6_4.3.0.dfsg.1-14_i386.deb
libx11-6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libx11-6-dbg_4.3.0.dfsg.1-14_i386.deb
libx11-6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libx11-6_4.3.0.dfsg.1-14_i386.deb
libx11-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libx11-dev_4.3.0.dfsg.1-14_i386.deb
libxaw6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxaw6-dbg_4.3.0.dfsg.1-14_i386.deb
libxaw6-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxaw6-dev_4.3.0.dfsg.1-14_i386.deb
libxaw6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxaw6_4.3.0.dfsg.1-14_i386.deb
libxaw7-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxaw7-dbg_4.3.0.dfsg.1-14_i386.deb
libxaw7-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxaw7-dev_4.3.0.dfsg.1-14_i386.deb
libxaw7_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxaw7_4.3.0.dfsg.1-14_i386.deb
libxext-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxext-dev_4.3.0.dfsg.1-14_i386.deb
libxext6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxext6-dbg_4.3.0.dfsg.1-14_i386.deb
libxext6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxext6_4.3.0.dfsg.1-14_i386.deb
libxft1-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxft1-dbg_4.3.0.dfsg.1-14_i386.deb
libxft1_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxft1_4.3.0.dfsg.1-14_i386.deb
libxi-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxi-dev_4.3.0.dfsg.1-14_i386.deb
libxi6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxi6-dbg_4.3.0.dfsg.1-14_i386.deb
libxi6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxi6_4.3.0.dfsg.1-14_i386.deb
libxmu-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxmu-dev_4.3.0.dfsg.1-14_i386.deb
libxmu6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxmu6-dbg_4.3.0.dfsg.1-14_i386.deb
libxmu6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxmu6_4.3.0.dfsg.1-14_i386.deb
libxmuu-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxmuu-dev_4.3.0.dfsg.1-14_i386.deb
libxmuu1-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxmuu1-dbg_4.3.0.dfsg.1-14_i386.deb
libxmuu1_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxmuu1_4.3.0.dfsg.1-14_i386.deb
libxp-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxp-dev_4.3.0.dfsg.1-14_i386.deb
libxp6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxp6-dbg_4.3.0.dfsg.1-14_i386.deb
libxp6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxp6_4.3.0.dfsg.1-14_i386.deb
libxpm-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxpm-dev_4.3.0.dfsg.1-14_i386.deb
libxpm4-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxpm4-dbg_4.3.0.dfsg.1-14_i386.deb
libxpm4_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxpm4_4.3.0.dfsg.1-14_i386.deb
libxrandr-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxrandr-dev_4.3.0.dfsg.1-14_i386.deb
libxrandr2-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxrandr2-dbg_4.3.0.dfsg.1-14_i386.deb
libxrandr2_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxrandr2_4.3.0.dfsg.1-14_i386.deb
libxt-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxt-dev_4.3.0.dfsg.1-14_i386.deb
libxt6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxt6-dbg_4.3.0.dfsg.1-14_i386.deb
libxt6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxt6_4.3.0.dfsg.1-14_i386.deb
libxtrap-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxtrap-dev_4.3.0.dfsg.1-14_i386.deb
libxtrap6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxtrap6-dbg_4.3.0.dfsg.1-14_i386.deb
libxtrap6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxtrap6_4.3.0.dfsg.1-14_i386.deb
libxtst-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxtst-dev_4.3.0.dfsg.1-14_i386.deb
libxtst6-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxtst6-dbg_4.3.0.dfsg.1-14_i386.deb
libxtst6_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxtst6_4.3.0.dfsg.1-14_i386.deb
libxv-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxv-dev_4.3.0.dfsg.1-14_i386.deb
libxv1-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxv1-dbg_4.3.0.dfsg.1-14_i386.deb
libxv1_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/libxv1_4.3.0.dfsg.1-14_i386.deb
pm-dev_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/pm-dev_4.3.0.dfsg.1-14_all.deb
proxymngr_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/proxymngr_4.3.0.dfsg.1-14_i386.deb
twm_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/twm_4.3.0.dfsg.1-14_i386.deb
x-dev_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/x-dev_4.3.0.dfsg.1-14_all.deb
x-window-system-core_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/x-window-system-core_4.3.0.dfsg.1-14_i386.deb
x-window-system-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/x-window-system-dev_4.3.0.dfsg.1-14_i386.deb
x-window-system_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/x-window-system_4.3.0.dfsg.1-14_all.deb
xbase-clients_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xbase-clients_4.3.0.dfsg.1-14_i386.deb
xdm_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xdm_4.3.0.dfsg.1-14_i386.deb
xfonts-100dpi-transcoded_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfonts-100dpi-transcoded_4.3.0.dfsg.1-14_all.deb
xfonts-100dpi_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfonts-100dpi_4.3.0.dfsg.1-14_all.deb
xfonts-75dpi-transcoded_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfonts-75dpi-transcoded_4.3.0.dfsg.1-14_all.deb
xfonts-75dpi_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfonts-75dpi_4.3.0.dfsg.1-14_all.deb
xfonts-base-transcoded_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfonts-base-transcoded_4.3.0.dfsg.1-14_all.deb
xfonts-base_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfonts-base_4.3.0.dfsg.1-14_all.deb
xfonts-cyrillic_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfonts-cyrillic_4.3.0.dfsg.1-14_all.deb
xfonts-scalable_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfonts-scalable_4.3.0.dfsg.1-14_all.deb
xfree86-common_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xfree86-common_4.3.0.dfsg.1-14_all.deb
xfree86_4.3.0.dfsg.1-14.diff.gz
  to pool/main/x/xfree86/xfree86_4.3.0.dfsg.1-14.diff.gz
xfree86_4.3.0.dfsg.1-14.dsc
  to pool/main/x/xfree86/xfree86_4.3.0.dfsg.1-14.dsc
xfs_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xfs_4.3.0.dfsg.1-14_i386.deb
xfwp_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xfwp_4.3.0.dfsg.1-14_i386.deb
xlibmesa-dev_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xlibmesa-dev_4.3.0.dfsg.1-14_all.deb
xlibmesa-dri-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa-dri-dbg_4.3.0.dfsg.1-14_i386.deb
xlibmesa-dri_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa-dri_4.3.0.dfsg.1-14_i386.deb
xlibmesa-gl-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa-gl-dbg_4.3.0.dfsg.1-14_i386.deb
xlibmesa-gl-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa-gl-dev_4.3.0.dfsg.1-14_i386.deb
xlibmesa-gl_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa-gl_4.3.0.dfsg.1-14_i386.deb
xlibmesa-glu-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa-glu-dbg_4.3.0.dfsg.1-14_i386.deb
xlibmesa-glu-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa-glu-dev_4.3.0.dfsg.1-14_i386.deb
xlibmesa-glu_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa-glu_4.3.0.dfsg.1-14_i386.deb
xlibmesa3-dbg_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xlibmesa3-dbg_4.3.0.dfsg.1-14_all.deb
xlibmesa3_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibmesa3_4.3.0.dfsg.1-14_i386.deb
xlibosmesa-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibosmesa-dev_4.3.0.dfsg.1-14_i386.deb
xlibosmesa4-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibosmesa4-dbg_4.3.0.dfsg.1-14_i386.deb
xlibosmesa4_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibosmesa4_4.3.0.dfsg.1-14_i386.deb
xlibs-data_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xlibs-data_4.3.0.dfsg.1-14_all.deb
xlibs-dbg_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xlibs-dbg_4.3.0.dfsg.1-14_all.deb
xlibs-dev_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xlibs-dev_4.3.0.dfsg.1-14_all.deb
xlibs-pic_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xlibs-pic_4.3.0.dfsg.1-14_all.deb
xlibs-static-dev_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibs-static-dev_4.3.0.dfsg.1-14_i386.deb
xlibs-static-pic_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xlibs-static-pic_4.3.0.dfsg.1-14_i386.deb
xlibs_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xlibs_4.3.0.dfsg.1-14_all.deb
xmh_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xmh_4.3.0.dfsg.1-14_i386.deb
xnest_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xnest_4.3.0.dfsg.1-14_i386.deb
xserver-common_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xserver-common_4.3.0.dfsg.1-14_i386.deb
xserver-xfree86-dbg_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xserver-xfree86-dbg_4.3.0.dfsg.1-14_i386.deb
xserver-xfree86_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xserver-xfree86_4.3.0.dfsg.1-14_i386.deb
xspecs_4.3.0.dfsg.1-14_all.deb
  to pool/main/x/xfree86/xspecs_4.3.0.dfsg.1-14_all.deb
xterm_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xterm_4.3.0.dfsg.1-14_i386.deb
xutils_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xutils_4.3.0.dfsg.1-14_i386.deb
xvfb_4.3.0.dfsg.1-14_i386.deb
  to pool/main/x/xfree86/xvfb_4.3.0.dfsg.1-14_i386.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 308783@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Fabio M. Di Nitto <fabbione@fabbione.net> (supplier of updated xfree86 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Wed, 01 Jun 2005 07:01:50 +0200
Source: xfree86
Binary: libx11-6-dbg libxtst6-dbg xserver-common xlibs-static-dev libxp6-dbg xbase-clients xlibmesa3-dbg libxtrap6-dbg xfonts-75dpi libxt6 libice6-dbg xmh libxaw6-dbg x-dev libxv1 libxext6-dbg xlibmesa-dev libxpm4 libxtst6 xlibmesa-gl-dev xfonts-cyrillic libx11-6 libsm6-dbg xlibs-pic xlibs-data x-window-system xfree86-common xlibmesa-dri xlibmesa3 libxv1-dbg libxrandr2 xlibmesa-glu libxaw7-dev xnest libxaw6 xterm libxp6 xlibmesa-dri-dbg libxrandr2-dbg libxmu6 xlibmesa-glu-dbg libx11-dev xlibs-static-pic libxpm4-dbg libxaw7-dbg libxmu6-dbg xlibmesa-glu-dev libxmuu-dev pm-dev libxext6 libxft1-dbg libxtst-dev libxv-dev libxp-dev twm x-window-system-dev libsm-dev xfonts-scalable libdps1-dbg libxmuu1-dbg xfwp libice6 libxmu-dev xlibs libdps-dev xserver-xfree86-dbg libxrandr-dev libsm6 xserver-xfree86 libdps1 proxymngr xfonts-base-transcoded libxaw6-dev lbxproxy x-window-system-core xutils xspecs libxtrap6 libice-dev libxt-dev xfs libxmuu1 libxi6-dbg xfonts-base xlibs-dbg libxpm-dev xlibmesa-gl xfonts-100dpi-transcoded libxtrap-dev xfonts-100dpi libxext-dev xfonts-75dpi-transcoded xlibosmesa4-dbg libxft1 libxi-dev xlibosmesa-dev xlibosmesa4 xvfb libxaw7 xlibmesa-gl-dbg xdm xlibs-dev libxi6 libxt6-dbg
Architecture: source i386 all
Version: 4.3.0.dfsg.1-14
Distribution: unstable
Urgency: high
Maintainer: Debian X Strike Force <debian-x@lists.debian.org>
Changed-By: Fabio M. Di Nitto <fabbione@fabbione.net>
Description: 
 lbxproxy   - Low Bandwidth X (LBX) proxy server
 libdps-dev - Display PostScript (DPS) client library development files
 libdps1    - Display PostScript (DPS) client library
 libdps1-dbg - Display PostScript (DPS) client library (unstripped)
 libice-dev - Inter-Client Exchange library development files
 libice6    - Inter-Client Exchange library
 libice6-dbg - Inter-Client Exchange library (unstripped)
 libsm-dev  - X Window System Session Management library development files
 libsm6     - X Window System Session Management library
 libsm6-dbg - X Window System Session Management library (unstripped)
 libx11-6   - X Window System protocol client library
 libx11-6-dbg - X Window System protocol client library (unstripped)
 libx11-dev - X Window System protocol client library development files
 libxaw6    - X Athena widget set library (version 6)
 libxaw6-dbg - X Athena widget set library (version 6, unstripped)
 libxaw6-dev - X Athena widget set library development files (version 6)
 libxaw7    - X Athena widget set library
 libxaw7-dbg - X Athena widget set library (unstripped)
 libxaw7-dev - X Athena widget set library development files
 libxext-dev - X Window System miscellaneous extension library development files
 libxext6   - X Window System miscellaneous extension library
 libxext6-dbg - X Window System miscellaneous extension library (unstripped)
 libxft1    - FreeType-based font drawing library for X (version 1)
 libxft1-dbg - FreeType-based font drawing library for X (version 1, unstripped)
 libxi-dev  - X Window System Input extension library development files
 libxi6     - X Window System Input extension library
 libxi6-dbg - X Window System Input extension library (unstripped)
 libxmu-dev - X Window System miscellaneous utility library development files
 libxmu6    - X Window System miscellaneous utility library
 libxmu6-dbg - X Window System miscellaneous utility library (unstripped)
 libxmuu-dev - lightweight X Window System miscellaneous utility library develop
 libxmuu1   - lightweight X Window System miscellaneous utility library
 libxmuu1-dbg - lightweight X Window System miscellaneous utility library (unstri
 libxp-dev  - X Window System printing extension library development files
 libxp6     - X Window System printing extension library
 libxp6-dbg - X Window System printing extension library (unstripped)
 libxpm-dev - X pixmap library development files
 libxpm4    - X pixmap library
 libxpm4-dbg - X pixmap library (unstripped)
 libxrandr-dev - X Window System Resize, Rotate and Reflection extension library d
 libxrandr2 - X Window System Resize, Rotate and Reflection extension library
 libxrandr2-dbg - X Window System Resize, Rotate and Reflection extension library (
 libxt-dev  - X Toolkit Intrinsics development files
 libxt6     - X Toolkit Intrinsics
 libxt6-dbg - X Toolkit Intrinsics (unstripped)
 libxtrap-dev - X Window System protocol-trapping extension library development f
 libxtrap6  - X Window System protocol-trapping extension library
 libxtrap6-dbg - X Window System protocol-trapping extension library (unstripped)
 libxtst-dev - X Window System event recording and testing extension library dev
 libxtst6   - X Window System event recording and testing extension library
 libxtst6-dbg - X Window System event recording and testing extension library (un
 libxv-dev  - X Window System video extension library development files
 libxv1     - X Window System video extension library
 libxv1-dbg - X Window System video extension library (unstripped)
 pm-dev     - proxy management protocol development files
 proxymngr  - X proxy services manager
 twm        - Tab window manager
 x-dev      - X protocol development files
 x-window-system - X Window System
 x-window-system-core - X Window System core components
 x-window-system-dev - X Window System development components
 xbase-clients - miscellaneous X clients
 xdm        - X display manager
 xfonts-100dpi - 100 dpi fonts for X
 xfonts-100dpi-transcoded - 100 dpi fonts for X (transcoded from ISO 10646-1)
 xfonts-75dpi - 75 dpi fonts for X
 xfonts-75dpi-transcoded - 75 dpi fonts for X (transcoded from ISO 10646-1)
 xfonts-base - standard fonts for X
 xfonts-base-transcoded - standard fonts for X (transcoded from ISO 10646-1)
 xfonts-cyrillic - Cyrillic fonts for X
 xfonts-scalable - scalable fonts for X
 xfree86-common - X Window System (XFree86) infrastructure
 xfs        - X font server
 xfwp       - X firewall proxy server
 xlibmesa-dev - XFree86 Mesa development libraries dummy package
 xlibmesa-dri - Mesa 3D graphics library modules [XFree86]
 xlibmesa-dri-dbg - Mesa 3D graphics library modules (unstripped) [XFree86]
 xlibmesa-gl - Mesa 3D graphics library [XFree86]
 xlibmesa-gl-dbg - Mesa 3D graphics library (unstripped) [XFree86]
 xlibmesa-gl-dev - Mesa 3D graphics library development files [XFree86]
 xlibmesa-glu - Mesa OpenGL utility library [XFree86]
 xlibmesa-glu-dbg - Mesa OpenGL utility library (unstripped) [XFree86]
 xlibmesa-glu-dev - Mesa OpenGL utility library development files [XFree86]
 xlibmesa3  - XFree86 Mesa libraries dummy package
 xlibmesa3-dbg - XFree86 Mesa unstripped libraries dummy package
 xlibosmesa-dev - Mesa off-screen rendering library development files [XFree86]
 xlibosmesa4 - Mesa off-screen rendering library [XFree86]
 xlibosmesa4-dbg - Mesa off-screen rendering library (unstripped) [XFree86]
 xlibs      - X Keyboard Extension (XKB) configuration data and metapackage
 xlibs-data - X Window System client data
 xlibs-dbg  - X Window System unstripped client libraries dummy package
 xlibs-dev  - X Window System client library development files dummy package
 xlibs-pic  - XFree86 static PIC libraries dummy package
 xlibs-static-dev - X Window System client library development files
 xlibs-static-pic - X Window System client extension library PIC archives
 xmh        - X interface to the MH mail system
 xnest      - nested X server
 xserver-common - files and utilities common to all X servers
 xserver-xfree86 - the XFree86 X server
 xserver-xfree86-dbg - the XFree86 X server (static version with debugging symbols)
 xspecs     - X protocol, extension, and library technical specifications
 xterm      - X terminal emulator
 xutils     - X Window System utility programs
 xvfb       - virtual framebuffer X server
Closes: 308783 309450 311184
Changes: 
 xfree86 (4.3.0.dfsg.1-14) unstable; urgency=high
 .
   Urgency set to high due to fix for security flaw (see below).
 .
   Changes by David Nusinow and Branden Robinson:
 .
   * Replace s_popen()-based fix for CAN-2004-0914 with a better fix from
     freedesktop.org xorg CVS.  There were several problems with s_popen(),
     some merely functional, and some themselves security-flawed.  There does
     not appear to be a MITRE CVE candidate ID for this problem.  The only
     differences between the Xpm library code in this package release and that
     in freedesktop.org xorg CVS HEAD as of 2005-05-26 are 1) whitespace
     differences; 2) RCS keyword differences; 3) preprocessor directives to
     support autotoolization of the library; 4) support for pre-ANSI C
     compilers in function declarations; 5) removal of some dead code in
     create.c; and 6) preprocessor-enforced ignorance of PutPixel32() on 64-bit
     systems (whose implementation was already disabled on 64-bit systems).
     (Closes: #308783)
 .
   Changes by Branden Robinson:
 .
   * Fix grammar error in Spanish debconf template translations (thanks, Steve
     Langasek).  (Closes: #309450)
 .
   * Grab fixes from freedesktop.org xorg CVS that make the DPMS extension
     header (dpms.h) and Xpm library header file (xpm.h) usable with C++ code
     by using the _XFUNCPROTO{BEGIN,END} macros instead of nothing at all (in
     the DPMS case) or a literal 'extern "C" {' construct (in the XPM case).
     C++ applications using the DPMS headers were likely to crash; see
     <URL: https://bugs.freedesktop.org/show_bug.cgi?id=830 >.  The DPMS fix
     also adds a header self-inclusion guard to dpms.h.
 .
   * Invert sense of tests invoking has_multiplexed_mouse; the comments were
     right, but the logic was exactly backwards.  This should fix warp-speed
     and left-handed configuration mouse device problems introduced (or simply
     not fixed for USB and PS/2 mouse users of Linux 2.6) in -13.  Thanks to
     Steve Langasek for eyeballing the code and catching my thinko.
     (Closes: #311184)
Files: 
 0bb5a14c74a6f6557518b0327525bd5f 2630 x11 optional xfree86_4.3.0.dfsg.1-14.dsc
 c0c0b8ccc69d3b980a727872787c809a 3633440 x11 optional xfree86_4.3.0.dfsg.1-14.diff.gz
 15625a69444902a617194ec91122a8b7 158806 libdevel optional pm-dev_4.3.0.dfsg.1-14_all.deb
 2b0f0b8c68acb2beb6d60f49c2afc4a4 215822 libdevel optional x-dev_4.3.0.dfsg.1-14_all.deb
 e132c80e9de7598b7224500496bd9550 4362440 x11 optional xfonts-100dpi_4.3.0.dfsg.1-14_all.deb
 2379e4cd75a841bdc0830caed67f72d2 8196942 x11 optional xfonts-100dpi-transcoded_4.3.0.dfsg.1-14_all.deb
 4c115d3431e1070359adbb842cabf4c0 3840286 x11 optional xfonts-75dpi_4.3.0.dfsg.1-14_all.deb
 03491456f93b824ed8011c82f68895b1 7074078 x11 optional xfonts-75dpi-transcoded_4.3.0.dfsg.1-14_all.deb
 0cac9cc1322cbcd4466a075087c6ede7 5489876 x11 optional xfonts-base_4.3.0.dfsg.1-14_all.deb
 891fe17891728ab81415be9e44249329 1203228 x11 optional xfonts-base-transcoded_4.3.0.dfsg.1-14_all.deb
 08cd950dd41507256cb0375203ff45f7 540516 x11 optional xfonts-cyrillic_4.3.0.dfsg.1-14_all.deb
 f09ee44a8f6f71dd95f5f3e01cad92da 900172 x11 optional xfonts-scalable_4.3.0.dfsg.1-14_all.deb
 edcc300a8de661b1a9413baf123ac193 814678 x11 optional xfree86-common_4.3.0.dfsg.1-14_all.deb
 38bb39f1ddeb6636978abf85a0d001a9 417414 libs optional xlibs_4.3.0.dfsg.1-14_all.deb
 eaea5aac7b14dc627fcdd7c685d8a570 906044 libs optional xlibs-data_4.3.0.dfsg.1-14_all.deb
 df62a862b694879ff1097c1739b9abd0 5833936 x11 optional xspecs_4.3.0.dfsg.1-14_all.deb
 77d8760d1e61d1f21d6481ba239318c5 158094 x11 optional x-window-system_4.3.0.dfsg.1-14_all.deb
 129cfdf4a541128b20ad178d4ea90c4e 157956 oldlibs extra xlibmesa3-dbg_4.3.0.dfsg.1-14_all.deb
 4b7360d44871858490217257d1a78215 157946 oldlibs optional xlibmesa-dev_4.3.0.dfsg.1-14_all.deb
 794207aef5caee035fce2826a5b4b7d9 158008 oldlibs extra xlibs-dbg_4.3.0.dfsg.1-14_all.deb
 922c0dc66827a7f61a58d995846e290b 158008 oldlibs extra xlibs-dev_4.3.0.dfsg.1-14_all.deb
 360ab73044da194fbbd0f20d8331dd85 157914 oldlibs extra xlibs-pic_4.3.0.dfsg.1-14_all.deb
 19dbdfd8eca6c1f8d371a46c202b7f29 249584 x11 optional lbxproxy_4.3.0.dfsg.1-14_i386.deb
 6e491bb7003992583b6357d20db6393f 285574 libs optional libdps1_4.3.0.dfsg.1-14_i386.deb
 cfe68dcc6f4c364c7b86bad6ab67c815 782188 libdevel extra libdps1-dbg_4.3.0.dfsg.1-14_i386.deb
 5efd048c4de6d72094a049c948f065fa 341646 libdevel optional libdps-dev_4.3.0.dfsg.1-14_i386.deb
 c933d1543874b967c5fb695cc2944a24 202900 libs optional libice6_4.3.0.dfsg.1-14_i386.deb
 6e09b9417f2f0cae74121da52a6866d7 285668 libdevel extra libice6-dbg_4.3.0.dfsg.1-14_i386.deb
 75a4ef20cfbbae3d3572e4743f48bf03 204700 libdevel optional libice-dev_4.3.0.dfsg.1-14_i386.deb
 0be24d5b228f6a6b4e9a1e7df80c3751 180654 libs optional libsm6_4.3.0.dfsg.1-14_i386.deb
 be5f124f4589dc800d8892da3dcf2a51 204752 libdevel extra libsm6-dbg_4.3.0.dfsg.1-14_i386.deb
 35c777a18c5b9dc02b39fd3d899be064 176088 libdevel optional libsm-dev_4.3.0.dfsg.1-14_i386.deb
 018afd68278d69f25501c9efe0b92b0c 724522 libs optional libx11-6_4.3.0.dfsg.1-14_i386.deb
 e9053c08c8c8fa8d026b1f83f10eb493 9606386 libdevel extra libx11-6-dbg_4.3.0.dfsg.1-14_i386.deb
 986061b5d5028ca0703b6dea2424e56d 1357886 libdevel optional libx11-dev_4.3.0.dfsg.1-14_i386.deb
 0c15f37fcece9e2acd5c54a096b83a2e 284800 libs optional libxaw6_4.3.0.dfsg.1-14_i386.deb
 91f8a812ecece1e8079ae6b85b7aaa27 889908 libdevel extra libxaw6-dbg_4.3.0.dfsg.1-14_i386.deb
 cfb000a60674f56512ceba602c16382c 413630 libdevel extra libxaw6-dev_4.3.0.dfsg.1-14_i386.deb
 3b7f4d341c61de0f1c59b45bac4f7b12 338010 libs optional libxaw7_4.3.0.dfsg.1-14_i386.deb
 f40e06f71d6d0a9b79dac9cba2f962d6 1024718 libdevel extra libxaw7-dbg_4.3.0.dfsg.1-14_i386.deb
 46a28a3dd18523439a8226bbb37d232b 413532 libdevel optional libxaw7-dev_4.3.0.dfsg.1-14_i386.deb
 e3091311d53dec7792caaa98af9e197c 187796 libs optional libxext6_4.3.0.dfsg.1-14_i386.deb
 b3772ecf9dcfa5efd77c888e9554d48e 506884 libdevel extra libxext6-dbg_4.3.0.dfsg.1-14_i386.deb
 f2ac6c4e5f2d1a5f1982355671d7f236 246282 libdevel optional libxext-dev_4.3.0.dfsg.1-14_i386.deb
 15e4309c0cda5df9ec12bfc870df1ce3 190156 libs optional libxft1_4.3.0.dfsg.1-14_i386.deb
 d8cbda19e0a1fe5e330b85255cf794a6 469170 libdevel extra libxft1-dbg_4.3.0.dfsg.1-14_i386.deb
 495e0a5023a70d655d0d27d130222f8b 178956 libs optional libxi6_4.3.0.dfsg.1-14_i386.deb
 39487ead2015087d6533eb007f7c2c6d 1166022 libdevel extra libxi6-dbg_4.3.0.dfsg.1-14_i386.deb
 4f3bdd9482cfcd4294557edd19edfe8c 230510 libdevel optional libxi-dev_4.3.0.dfsg.1-14_i386.deb
 fc257532851e09a76d8abfb66c45e64d 209240 libs optional libxmu6_4.3.0.dfsg.1-14_i386.deb
 396d8296a84d01a5a7dff715bca64986 659366 libdevel extra libxmu6-dbg_4.3.0.dfsg.1-14_i386.deb
 b937201c2e90fa5de1dd5bcb111e9873 217768 libdevel optional libxmu-dev_4.3.0.dfsg.1-14_i386.deb
 628f2622136714b12cf8c96973a0144a 171136 libs optional libxmuu1_4.3.0.dfsg.1-14_i386.deb
 31fadca747461957f0d87d6ae2cac88f 207840 libdevel extra libxmuu1-dbg_4.3.0.dfsg.1-14_i386.deb
 c55eca94e0394b8947539cb75a093141 162480 libdevel optional libxmuu-dev_4.3.0.dfsg.1-14_i386.deb
 8ba368424d62f6bff3d3d6c8b97b58e9 178084 libs optional libxp6_4.3.0.dfsg.1-14_i386.deb
 3ad04417eb80d6570dab314969122d40 564832 libdevel extra libxp6-dbg_4.3.0.dfsg.1-14_i386.deb
 83c5b944b7253fc077d2a6b076b824ec 178404 libdevel optional libxp-dev_4.3.0.dfsg.1-14_i386.deb
 1032f27eee6b7f29268e0572ab68ed77 195254 libs optional libxpm4_4.3.0.dfsg.1-14_i386.deb
 13fc3e54bba5dd914a6968e2f647a34d 244768 libdevel extra libxpm4-dbg_4.3.0.dfsg.1-14_i386.deb
 6493b3017b761b4b32b28fbd224632fb 193044 libdevel optional libxpm-dev_4.3.0.dfsg.1-14_i386.deb
 fc758de2f6268971f5d41f87fc8eddbc 170896 libs optional libxrandr2_4.3.0.dfsg.1-14_i386.deb
 b81e46a4ed0fa3bc5ceddd0ec7030dcf 199722 libdevel extra libxrandr2-dbg_4.3.0.dfsg.1-14_i386.deb
 b0162cd94b76be6268bfb7b78984a545 170466 libdevel optional libxrandr-dev_4.3.0.dfsg.1-14_i386.deb
 cf17665b85df64d0b74d8714c4b4ab6e 328758 libs optional libxt6_4.3.0.dfsg.1-14_i386.deb
 c959f8685efe7e4f63b7f7830523bfe4 1530540 libdevel extra libxt6-dbg_4.3.0.dfsg.1-14_i386.deb
 999baf29f1362fbd91894caa5e886545 613802 libdevel optional libxt-dev_4.3.0.dfsg.1-14_i386.deb
 9a028a895aa2d1477c6c688d3213a4b9 179938 libs optional libxtrap6_4.3.0.dfsg.1-14_i386.deb
 39eb591234d00bc8eb3f1d83e1898cdb 409604 libdevel extra libxtrap6-dbg_4.3.0.dfsg.1-14_i386.deb
 ed190db0a663f069def5c0ffdeaea25a 184258 libdevel optional libxtrap-dev_4.3.0.dfsg.1-14_i386.deb
 9edb524b19b015d3bc8fde1edaa8d74c 173866 libs optional libxtst6_4.3.0.dfsg.1-14_i386.deb
 c5520387534d23cfdc93afd50bc4fb19 235900 libdevel extra libxtst6-dbg_4.3.0.dfsg.1-14_i386.deb
 776b9a5cc1934ec9e47da90a55fc6e72 169306 libdevel optional libxtst-dev_4.3.0.dfsg.1-14_i386.deb
 d37ed643972757a0d370ec732fdbd035 171994 libs optional libxv1_4.3.0.dfsg.1-14_i386.deb
 33a9225195a108c7f9f06f1c14ea07a7 202500 libdevel extra libxv1-dbg_4.3.0.dfsg.1-14_i386.deb
 4936a24ba98787eadd16662a9560bfdb 189980 libdevel optional libxv-dev_4.3.0.dfsg.1-14_i386.deb
 3381eecc9e90517013dcb6cf16df43d0 182104 x11 optional proxymngr_4.3.0.dfsg.1-14_i386.deb
 bd7a029fcfa8b1b707aca2ebb4ed5745 264384 x11 optional twm_4.3.0.dfsg.1-14_i386.deb
 4131a3b1b01544789b8bace8e223c192 1940140 x11 optional xbase-clients_4.3.0.dfsg.1-14_i386.deb
 441b00aa8727f5a28cd73e45c29c3fdf 308448 x11 optional xdm_4.3.0.dfsg.1-14_i386.deb
 cacd870db46b88c5d27634696d976afe 495908 x11 optional xfs_4.3.0.dfsg.1-14_i386.deb
 a6125ad8d0a834307b2d4460147b59ab 179948 x11 optional xfwp_4.3.0.dfsg.1-14_i386.deb
 44ee53db9654816cbd7d15ba33c27478 5008506 x11 optional xlibmesa-dri_4.3.0.dfsg.1-14_i386.deb
 6e0b1466a00aa3f0bacb31eb9685d105 49493254 x11 optional xlibmesa-dri-dbg_4.3.0.dfsg.1-14_i386.deb
 95281c5606c57c8af0b206bf7497245b 282732 libs optional xlibmesa-gl_4.3.0.dfsg.1-14_i386.deb
 26daf1a27ee529f259b79ab74ebbf920 1230046 libdevel extra xlibmesa-gl-dbg_4.3.0.dfsg.1-14_i386.deb
 582ccfaefb87d16bb0b54ff98459a03e 704506 libdevel optional xlibmesa-gl-dev_4.3.0.dfsg.1-14_i386.deb
 5ba5582267027fa8f126a52df3bce9bf 365418 libs optional xlibmesa-glu_4.3.0.dfsg.1-14_i386.deb
 b7821f41002e0ba7ed5f717e06531921 1110690 libdevel extra xlibmesa-glu-dbg_4.3.0.dfsg.1-14_i386.deb
 49eac6524b49a637a7a41c030833bbed 434468 libdevel optional xlibmesa-glu-dev_4.3.0.dfsg.1-14_i386.deb
 3d1121b7506e898d0b2e5616d33077c2 661496 libs optional xlibosmesa4_4.3.0.dfsg.1-14_i386.deb
 eedec639ed50669392d64c228e61fa9a 4580406 libdevel extra xlibosmesa4-dbg_4.3.0.dfsg.1-14_i386.deb
 211f87e13d146010e829237e27be05ba 789630 libdevel optional xlibosmesa-dev_4.3.0.dfsg.1-14_i386.deb
 7b3eba163815a0811b0624abb01ae6dc 853904 libdevel optional xlibs-static-dev_4.3.0.dfsg.1-14_i386.deb
 71fb194a3934db54d10a61ad55cc1d45 383904 libdevel extra xlibs-static-pic_4.3.0.dfsg.1-14_i386.deb
 221095b120941f0a68c32a52f6cd5850 226310 mail extra xmh_4.3.0.dfsg.1-14_i386.deb
 af1659610f7d04a53d767cb0fe657759 1465938 x11 optional xnest_4.3.0.dfsg.1-14_i386.deb
 02f48f6ff3b545f8be599f541730c826 336168 x11 optional xserver-common_4.3.0.dfsg.1-14_i386.deb
 4632bc8b2d6c85bc9e59d624502f1e64 5742308 x11 optional xserver-xfree86_4.3.0.dfsg.1-14_i386.deb
 29aa0ce3f9b54bf335c731287ee7985b 54911358 x11 extra xserver-xfree86-dbg_4.3.0.dfsg.1-14_i386.deb
 a99a379d723c207afaab23a7333bd1dc 508610 x11 optional xterm_4.3.0.dfsg.1-14_i386.deb
 c719f32813168944472e212a73986985 911240 x11 optional xutils_4.3.0.dfsg.1-14_i386.deb
 b5f390dfd0a3b18e4dc313805b57ae89 1602280 x11 optional xvfb_4.3.0.dfsg.1-14_i386.deb
 a0069d439dbd5f280c79d2e0a8f1545c 158168 x11 optional x-window-system-core_4.3.0.dfsg.1-14_i386.deb
 e5a462c83f790d6686034503b75e06af 158222 x11 extra x-window-system-dev_4.3.0.dfsg.1-14_i386.deb
 4d55b37450dce691ee45463bb43f1ece 157970 oldlibs optional xlibmesa3_4.3.0.dfsg.1-14_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFCnVFRhCzbekR3nhgRAhPbAJ9T21WqMkHdBmoawBXtNDlVUckWhgCfX0+Q
qiL1rISiKtOJO+Jqn5yuLzg=
=xI23
-----END PGP SIGNATURE-----




Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Tue Aug 14 22:46:15 2018; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.