The debian-private mailing list leak, part 1. Volunteers have complained about Blackmail. Lynchings. Character assassination. Defamation. Cyberbullying. Volunteers who gave many years of their lives are picked out at random for cruel social experiments. The former DPL's girlfriend Molly de Blanc is given volunteers to experiment on for her crazy talks. These volunteers never consented to be used like lab rats. We don't either. debian-private can no longer be a safe space for the cabal. Let these monsters have nowhere to hide. Volunteers are not disposable. We stand with the victims.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Guy: Please change "frozen" to "stable" and release Debian 1.3 .



joost@rulcmc.leidenuniv.nl (joost witteveen) writes:

> I always thought this would open you to other security exploits, allowing
> other users to snoop on your xterm's.

Correct, because the ptys must then be world-readable.

> Isn't a better solution to just not use xterm, but use rxvt instead?
> (ldd rxvt doesn't show a libXt dependancy of rxvt).?

Yes, that might work.

> Is there an alternative?

Waiting until 3.3 is out, or making another 3.2 release.

It's interesting that we had this EXACT SAME problem with 1.2 - a
libXt overrun discovered days before the release.  But then, we
already had a fixed version of XFree86 in unstable so we could just
move it to frozen.


Guy


--
TO UNSUBSCRIBE FROM THIS MAILING LIST: e-mail the word "unsubscribe" to
debian-private-request@lists.debian.org . 
Trouble?  e-mail to templin@bucknell.edu .