initial import of xrdb-1.0.9. fixes CVE-2011-0465: By crafting hostnames with shell escape characters, arbitrary commands can be executed in a root environment when a display manager reads in the resource database via xrdb. These specially crafted hostnames can occur in two environments: * Hosts that set their hostname via DHCP * Hosts that allow remote logins via xdmcp i will send pullups for netbsd-5, and see what netbsd-5 xfree and netbsd-4 need as well. |