Dear all,
the X2Go project is proud to announce a new release of the X2Go
component ,,x2goserver''.
This release of X2Go Server is a hot-fix release. The fixes described
below have been released via the Baikal LTS branch of X2Go Server
(version 4.0.0.9). All fixes of the LTS version are included in
this version of X2Go Server (4.0.1.11).
Together with two of our customers (Kelyon IT, LinDix.NL) and their
technicians' expertise we could narrow down X2Go session startup
problems in cases where a dot "." occurred in session ID strings.
Those issues could be caused by usernames containing dots or by custom
commands containing dots.
This version of X2Go Server should fix those issues while still being
nearly as strict about allowed session ID characters as introduced by
the previous version of X2Go Server (4.0.1.10 / 4.0.0.8 LTS).
X2Go Component: x2goserver
Version: 4.0.1.11
Status: RELEASE
Date: Mon, 06 Jan 2014 18:24:49 +0100
Fixes these bug report(s): 391
Changes:
x2goserver (4.0.1.11) RELEASED; urgency=low
.
* New upstream version (4.0.1.11):
- Fix x2gofm.desktop syntax. (Fixes: #391).
- Include all achievements from LTS release branch (as of version
4.0.0.9).
* x2goserver.spec:
- Enhance requirement of desktop-file-utils, validate x2gofm.desktop
during package build.
Regards,
Mike Gabriel
--
DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148
GnuPG Key ID 0x25771B31
mail: mike.gabriel(a)das-netzwerkteam.de, http://das-netzwerkteam.de
freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.x…
Dear all,
the X2Go project is proud to announce a new release of the X2Go
component ,,x2goserver''.
This release of X2Go Server is a hot-fix release. Together with two
of our customers (Kelyon IT, LinDix.NL) and their technicians' expertise
we could narrow down X2Go session startup problems in cases where a dot
"." occurred in session ID strings.
Those issues could be caused by usernames containing dots or by custom
commands containing dots.
This version of X2Go Server should fix those issues while still being
nearly as strict about allowed session ID characters as introduced by
the previous version of X2Go Server (4.0.1.10 / 4.0.0.8 LTS).
X2Go Component: x2goserver
Version: 4.0.0.9
Status: RELEASE
Date: Mon, 06 Jan 2014 18:21:36 +0100
Changes:
x2goserver (4.0.0.9) RELEASED; urgency=low
.
* New upstream version (4.0.0.9):
- Sanitize session name in x2gostartagent, as well. Fixes problems
with custom session commands containing characters that get
sanitized out.
- Allow dots (".") in sanitized session names.
Regards,
Mike Gabriel
--
DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148
GnuPG Key ID 0x25771B31
mail: mike.gabriel(a)das-netzwerkteam.de, http://das-netzwerkteam.de
freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.x…
Dear all,
the X2Go project is proud to announce a new release of the X2Go
component ,,nx-libs''.
New gains of this version of ,,nx-libs'' are:
o Reduce the code base to 15M (3.5.0.21: 16M, earlier versions 21M)
and drop shipped libraries that are not needed for building nxagent/
x2goagent.
o Fix FTBFS on Debian unstable.
o Fix FTBFS on Mac OS X Mavericks.
o Ship nx-libs.spec in upstream tarball as reference (and for our
RPM build system on http://jenkins.x2go.org)
X2Go Component: nx-libs
Version: 3.5.0.22
Status: RELEASE
Date: Sat, 04 Jan 2014 21:39:17 +0100
Fixes these bug report(s): 314 337 370
Changes:
nx-libs (3.5.0.22) RELEASED; urgency=low
.
[ Mirraz Mirraz ]
* Add patch: 603_nx-X11_compilation_warnings.full.patch. Fix 3
evident bugs:
one implicit function declaration issue and two array index out of bounds
issues. (Fixes: #314).
.
[ Mike Gabriel ]
* Add patch 604_nx-X11_recent-freetype-API.full.patch. Fix FTBFS against
recent (>= 2.5.0) libfreetype6 API.
* Refresh patch:
600_nx-X11+nxcompext+nxcompshad_unique-libnames.full.patch.
* Improve patch:
601_nx-X11_build-option-changes-to-not-use-bundled-libraries.full.patch.
Improvements taken from the current Fedora package. Thanks to Orion
Paplowski!!! Also adapt roll-tarball.sh do dropping more bundled
libraries.
* Rename patch: 302_nxagent_configurable-keystrokes.full.patch to
320_nxagent_configurable-keystrokes.full.patch.
* debian/source/format:
+ Switch to format 1.0.
* debian/control:
+ Add libfreetype6-dev to Build-Depends: field.
+ Drop symlinking libNX_xrandr for setting a custom
LD_LIBRARY_PATH. Not in
use anymore and not recommended at all to have that.
+ Make sure all nx-libs components depend on the very same version.
* debian/rules:
+ Remove bundled libraries from source tree before building the package.
* nx-libs.spec:
+ Ship nx-libs.spec (RPM package definitions) in upstream
project. (Thanks
to the Fedora package maintainers). File differs from the Fedora file
already.
+ Clear (Fedora package) changelog.
+ Use local tarball, don't expect ,,-full'' in tarball name.
+ The RPM macro for the linker flags does not exist on EPEL.
Thus, hardcode
__global_ldflags macro for EPEL builds.
+ Enable Xinerama support for RPM packages. (Fixes: #370).
.
[ Clemens Lang ]
* Add patch
605_nxcomp_Types.h-dont-use-STL-internals-on-libc++.full.patch. Fix
FTBFS of nx-libs-lite on Mac OS X Mavericks. (Fixes: #337).
Regards,
Mike Gabriel
--
DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148
GnuPG Key ID 0x25771B31
mail: mike.gabriel(a)das-netzwerkteam.de, http://das-netzwerkteam.de
freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.x…
Dear all,
the X2Go project is proud to announce a new release of the X2Go
component ,,x2goserver''.
This release pulls in all changes that got introduced in our Baikal
LTS release 4.0.0.8, including a severe vulnerability in
x2gocleansessions. Gains of the LTS version 4.0.0.8 of ,,x2goserver''
are:
o Improve parsing of the NX session.log file. Fix session
suspending/resuming when in fails in some occasions.
o Fix severe vulnerability in x2gocleansessions.
o Sanitize session ID string, port numbers, display numbers
and agent PID numbers before writing them as strings to the
session DB.
Please note::: This release fixes a severe vulnerability in X2Go Server
that allowed an attacker with user permissions to gain root access to
the X2Go Server machine. Everyone, please upgrade your X2Go Server
installations.
New gains of the version 4.0.1.10 of ,,x2goserver'' are:
o Fix x2goresume-session that we broke in 4.0.1.9.
o Fix the x2goserver-fmbindings Makefile.
o Allow enabling/disabling of TCP listening of x2goagent.
o Provide Xsession support for RPM based distribution.
This version of X2Go Server is the first version that we as X2Go upstream
also provide as RPM packages for Fedora [1] and EPEL-5 and EPEL-6 [2].
[1] http://wiki.x2go.org/doku.php/wiki:repositories:fedora
[2] http://wiki.x2go.org/doku.php/wiki:repositories:epel
X2Go Component: x2goserver
Version: 4.0.1.10
Status: RELEASE
Date: Fri, 03 Jan 2014 11:34:36 +0100
Fixes these bug report(s): 354 355
Changes:
x2goserver (4.0.1.10) RELEASED; urgency=low
.
* New upstream version (4.0.1.10):
- Fix x2goresume-session. The several parameters placed into the
NX options
file are expected by x2goresume-session at very specific
positions. This
we broke by trying to fix the fullscreen/geometry issue in
x2gostartagent.
Thanks to Harvey Eneman for tracking this down!!! (Fixes: #355).
- x2goserver-fmbindings/Makefile: install x2gofm.
- x2goserver-fmbindings/Makefile: install share/applications and
share/mime.
- x2goserver-printing/Makefile: create feature.d directory
before installing
files into it.
- Handle TCP listening of x2goagent in x2goagent.options. (Fixes: #354).
- Clean up Makefiles, remove commented out lines.
- Use xkb ruleset 'base' rather than xfree86 as on RHEL systems the
xfree86 symlink to base ruleset does not exist.
- Grab systemd service file from Fedora and ship it upstream.
- Provide RHEL/Fedora support in x2goserver-xsession.
- Only sanity check for existence of /etc/x2go/Xsession.d on Debian
(derived) systems.
- Provide man page for x2goserver.conf.
* x2goserver.spec:
+ Ship x2goserver.spec (RPM package definitions) in upstream project.
(Thanks to the Fedora package maintainers). File differs from
the Fedora
file already.
+ Add init script for RPM based distro. Taken from the Fedora
package.
+ Clear (Fedora package) changelog.
Regards,
Mike Gabriel
--
DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148
GnuPG Key ID 0x25771B31
mail: mike.gabriel(a)das-netzwerkteam.de, http://das-netzwerkteam.de
freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.x…
Dear all,
the X2Go project is proud to announce a new LTS release of the X2Go
component ,,x2goserver''.
Please note::: This release fixes a severe vulnerability in X2Go Server
that allowed an attacker with user permissions in previous versions of
X2Go Server to gain root access to the X2Go Server machine. We highly
recommend everyone to upgrade their X2Go Server installations.
New gains of this LTS version of ,,x2goserver'' are:
o Improve parsing of the NX session.log file. Fix session
suspending/resuming when in fails in some occasions.
o Fix severe vulnerability in x2gocleansessions.
o Sanitize session ID string, port numbers, display numbers
and agent PID numbers before writing them as strings to the
session DB.
X2Go Component: x2goserver
Version: 4.0.0.8
Status: RELEASE
Date: Fri, 03 Jan 2014 11:30:54 +0100
Fixes these bug report(s): 347 356
Changes:
x2goserver (4.0.0.8) RELEASED; urgency=low
.
* New upstream version (4.0.0.8):
- Use mktemp instead of tempfile (because Fedora does not have
the tempfile
binary). (Fixes: #347).
- Replace makepasswd by pwgen (because Fedora does not have makepasswd).
- Improve parsing of the NX session.log file where unexpected
extra logging
takes place during session suspension/resumption. Thanks to
Gerald Richter
for finding this!!! (Fixes: #356).
- Avoid one argument system calls and backticks in x2gocleansessions and
x2golistsessions_root.
- Avoid one argument system calls and backticks in x2golistsessions.
- Avoid one argument system calls and backticks in x2goprint.
- Avoid backticks in x2goshowblocks, move script to
<prefix>/sbin/ as it is
for being run with root privileges.
- Sanitize session ID string, port numbers, display numbers and
agent PID
numbers before writing them as strings to the session DB.
Regards,
Mike Gabriel
--
DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
fon: +49 (1520) 1976 148
GnuPG Key ID 0x25771B31
mail: mike.gabriel(a)das-netzwerkteam.de, http://das-netzwerkteam.de
freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.x…