14 Feb 2004 mharris   » (Master)

Boy, did this week's XFree86 security problems in libXfont ever suck. As soon as I had packages available to fix the first issue, the second issue was discovered. As soon as I had packages available to fix the second issue, the third issue was discovered. Quite a patch juggling contest to say the least. Nonetheless, that nightmare is now finally over - for now at least. I'm smart enough though to realize this nightmare isn't totally over yet. There is 350Mb of files in a full XFree86 source code tree, and while not all of it is actual source code, there is lots of code there for people to play with and have fun.

Thank God that most people, black hats included are frightened at X source code and generally wont touch it with a 10 foot pole.

Once all mainstream distributions begin shipping the modularized and autotooled freedesktop.org xlibs packages, the amount of pain which occurs when security issues are found will hopefully subside. The entire source tree really needs a heavy security audit, as well as a general cleanup. There's a lot of cruft there that hasn't been seen by human eyes for over 10 or more years.

Latest blog entries     Older blog entries

New Advogato Features

FOAF updates: Trust rankings are now exported, making the data available to other users and websites. An external FOAF URI has been added, allowing users to link to an additional FOAF file.

Keep up with the latest Advogato features by reading the Advogato status blog.

If you're a C programmer with some spare time, take a look at the mod_virgule project page and help us with one of the tasks on the ToDo list!