https://bugzilla.novell.com/show_bug.cgi?id=698250
https://bugzilla.novell.com/show_bug.cgi?id=698250#c35
--- Comment #35 from Vincent Untz
feel free to just submit to openSUSE:12.1:Test so we get an update staged already.
Talking to Richard, he feels an update to 0.0.15 is worth it. Do we want to take the update to fix the security issue? Here's the relevants bits from NEWS; it's really about bug fixes: =========================== Version 0.1.15 ~~~~~~~~~~~~~~ Released: 2011-11-26 Notes: - This release fixes an important security bug: CVE-2011-4349. - It is recommended all users update to this version, or backport these patches: * http://gitorious.org/colord/master/commit/1fadd90afcb4bbc47513466ee9bb1e4a86... * http://gitorious.org/colord/master/commit/36549e0ed255e7dfa7852d08a75dd5f00c... New Features: - Add a native driver for the Hughski ColorHug hardware (Richard Hughes) - Export cd-math as three projects are now using it (Richard Hughes) Bugfixes: - Documentation fixes and improvements (Laurent Martelli) - Do not crash the daemon if adding the device to the db failed (Richard Hughes) - Do not match any sensor device with a kernel driver (Richard Hughes) - Don't be obscure when the user passes a device-id to colormgr (Richard Hughes) - Fix a memory leak when getting properties from a device (Richard Hughes) - Fix colormgr device-get-default-profile (Richard Hughes) - Fix some conection bugs in colormgr (Florian Höch, Richard Hughes) - Fix some potential SQL injections (Ludwig Nussel, Vincent Untz) - Make gusb optional (Ludwig Nussel) - Only use the udev USB helper if the PID and VID have matches (Richard Hughes) - Output the Huey calibration matrices when dumping the sensor (Richard Hughes) Version 0.1.14 ~~~~~~~~~~~~~~ Released: 2011-11-01 Translations: New Features: - Add defines for the i1 Display 3 (Richard Hughes) - Add two more DATA_source values to the specification (Richard Hughes) - Align the output from colormgr get-devices and get-profiles (Richard Hughes) - Allow cd-fix-profile to append and edit new metadata (Richard Hughes) Bugfixes: - Ensure non-native device are added with no driver module (Richard Hughes) - Split the sensor and device udev code (Richard Hughes) =========================== -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.