Announcement

Collapse
No announcement yet.

X.Org Hit Hard By A Large Batch Of Security Vulnerabilities

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #11
    Wayland would solve many of these.

    Comment


    • #12
      We've always known that X is a security disaster, but it wasn't clear until now just how broken it is.

      This POS is unsalvageable.

      Comment


      • #13
        Wayland IS here. The desktops are almost here. Apps (firefox, libre, thunderbird -the big ones) on the other hand need love.

        Comment


        • #14
          Can we get mouse acceleration control in Wayland now, so we could move to the future and just leave this mess behind us? :/

          Comment


          • #15
            Originally posted by gutigen View Post
            Can we get mouse acceleration control in Wayland now, so we could move to the future and just leave this mess behind us? :/
            Install libinput-0.7.
            Haven't tried it, not sure if the compositors can make use of it, but the support is there (along with proper touch point scroll support).

            Comment


            • #16
              Just received xserver update 1.16.2.901 Those security vulnerabilities fixed

              Comment


              • #17
                Just went through the CVEs to check what I need to patch in tinyx (the Puppy version, not the TinyCore version!), and found that of 13 CVEs, at least 6 are not present in the code I have (GLX, DRI*, and DBE are all missing, and Xinput seems to be partial and disabled); one affects something that isn't built (SECURE_RPC); a couple are at least in part regressions, and I'll have to look at the remainder in more detail.

                Comment


                • #18
                  :gasp:

                  Linux may now have reached .00001% the vulnerability level of windows!



                  J/K, don't intend to start any flame wars just couldn't help myself.

                  Comment


                  • #19
                    Originally posted by kenjitamura View Post
                    :gasp:

                    Linux may now have reached .00001% the vulnerability level of windows!



                    J/K, don't intend to start any flame wars just couldn't help myself.
                    Remember the days when everyone ran their PCs as one, single, root-equivalent user? And now you have a bug that can crash an application and maybe get root access and it's considered a critical security vulnerability.

                    Just think... Windows 95 is just one big zero-day exploit.

                    Comment


                    • #20
                      Originally posted by johnc View Post
                      Remember the days when everyone ran their PCs as one, single, root-equivalent user? And now you have a bug that can crash an application and maybe get root access and it's considered a critical security vulnerability.

                      Just think... Windows 95 is just one big zero-day exploit.
                      Well, to be honest, every Windows that doesn't inherit security systems from Windows NT is just one big zero-day exploit

                      Comment

                      Working...
                      X