Path to this page:
Subject: CVS commit: pkgsrc/x11/libICE
From: Thomas Klausner
Date: 2019-11-13 22:51:24
Message id: 20191113215124.DE448FA95@cvs.NetBSD.org
Log Message:
libICE: update to 1.0.10.
This release provides a fix for CVE-2017-2626 for platforms which don't have
arc4random_buf() in their default libraries but do have getentropy(), such
as Linux platforms with a kernel version of 3.17 or newer and a glibc version
of 2.25 or newer. (libICE 1.0.9 already ensured that arc4random_buf()
is used on platforms that have it to provide sufficient entropy in ICE
key generation, but left other platforms with the weaker methods. Linux
platforms could also have linked against libbsd to use arc4random_buf()
with libICE 1.0.9 for stronger keys.)
Files: