A collection of minor fixes since 2.0.1, including CVEs 2017-13720 and 2017-13722. Adam Jackson (5): configure: Use -fvisibility=hidden if available autogen: Set a default subject prefix for patches freetype: Fix a logic error in computing face name readme: Update for libXfont 2.0 interface change libXfont 2.0.2 Emil Velikov (1): autogen.sh: use quoted string variables Jeremy Huddleston Sequoia (5): FreeType: Correct an allocation size bitmap: Bail out on invalid input to FontFileMakeDir instead of calling calloc for 0 bytes fserve: Silence a -Wformat warning fstrans: Remove unused foo() function fserve: Fix a buffer read overrun in _fs_client_access Keith Packard (1): Revert "Add compiler warning flags". Leave warning fixes. Michal Srb (2): Check for end of string in PatternMatch (CVE-2017-13720) pcfGetProperties: Check string boundaries (CVE-2017-13722) Peter Hutterer (1): autogen.sh: use exec instead of waiting for configure to finish git tag: libXfont2-2.0.2 https://xorg.freedesktop.org/archive/individual/lib/libXfont2-2.0.2.tar.bz2 MD5: d39e6446e46f939486d1a8b856e8b67b libXfont2-2.0.2.tar.bz2 SHA1: d5117914a026b3fd47123cb1c2a22daaae3b63e4 libXfont2-2.0.2.tar.bz2 SHA256: 94088d3b87f7d42c7116d9adaad155859e93330c6e47f5989f2de600b9a6c111 libXfont2-2.0.2.tar.bz2 SHA512: d62b0c3d663a2c668796cca8c6c2a90f83feeae1253b7d946668d33502cd8099c963285b88db4f745efb0d4ff783c118eb3d84cb8e6e1724586e1ef2be23e593 libXfont2-2.0.2.tar.bz2 PGP: https://xorg.freedesktop.org/archive/individual/lib/libXfont2-2.0.2.tar.bz2.sig https://xorg.freedesktop.org/archive/individual/lib/libXfont2-2.0.2.tar.gz MD5: 325233b04b715a93fa6548004a21c1c9 libXfont2-2.0.2.tar.gz SHA1: 3df365812830d7c19f9c71cffc633b82eaee726d libXfont2-2.0.2.tar.gz SHA256: b82dd7f5c5c4820dfced428da8bfc13a8cd25ce25e8119d337ae0bc6f9507814 libXfont2-2.0.2.tar.gz SHA512: 719ba126aa058eaa0b24a2b475be67391e674cccc0a5cb5e12e3b0150bab82560102e41599d945704dc07e1e854736ebfcf27d97faf042931f9591e7d1c64632 libXfont2-2.0.2.tar.gz PGP: https://xorg.freedesktop.org/archive/individual/lib/libXfont2-2.0.2.tar.gz.sig - ajax -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 659 bytes Desc: This is a digitally signed message part URL: <https://lists.x.org/archives/xorg-announce/attachments/20171011/510750e3/attachment.sig>