[ubuntu/hirsute-proposed] xorg-server 2:1.20.9-2ubuntu3 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Wed Dec 2 14:38:15 UTC 2020


xorg-server (2:1.20.9-2ubuntu3) hirsute; urgency=medium

  * SECURITY UPDATE: out of bounds memory accesses on too short request
    - debian/patches/CVE-2020-14360.patch: check SetMap request length
      carefully in xkb/xkb.c.
    - CVE-2020-14360
  * SECURITY UPDATE: multiple heap overflows
    - debian/patches/CVE-2020-25712.patch: add bounds checks in xkb/xkb.c.
    - CVE-2020-25712

Date: Wed, 02 Dec 2020 09:16:47 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu X-SWAT <ubuntu-x at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/xorg-server/2:1.20.9-2ubuntu3
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 02 Dec 2020 09:16:47 -0500
Source: xorg-server
Architecture: source
Version: 2:1.20.9-2ubuntu3
Distribution: hirsute
Urgency: medium
Maintainer: Ubuntu X-SWAT <ubuntu-x at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 xorg-server (2:1.20.9-2ubuntu3) hirsute; urgency=medium
 .
   * SECURITY UPDATE: out of bounds memory accesses on too short request
     - debian/patches/CVE-2020-14360.patch: check SetMap request length
       carefully in xkb/xkb.c.
     - CVE-2020-14360
   * SECURITY UPDATE: multiple heap overflows
     - debian/patches/CVE-2020-25712.patch: add bounds checks in xkb/xkb.c.
     - CVE-2020-25712
Checksums-Sha1:
 e235c8225e7e5a732c79e84fce704f7e80fb1c43 4563 xorg-server_1.20.9-2ubuntu3.dsc
 29e8812403e19c6f9ad0f09dd11c176e706751d2 221824 xorg-server_1.20.9-2ubuntu3.diff.gz
 5ea49a7a84554d610d67adfdf642a66196d21b30 12206 xorg-server_1.20.9-2ubuntu3_source.buildinfo
Checksums-Sha256:
 392fbd3f60207486f16cde042235f2cb413a4381f8d97061b3e5a758aad9ae64 4563 xorg-server_1.20.9-2ubuntu3.dsc
 5f1e29864da1becf97bfdec382f16d19cc1609b8afef2e5dacae643956464a9a 221824 xorg-server_1.20.9-2ubuntu3.diff.gz
 a41e332a96dfe2656e7f2a42e2d86cb62e4a4e2f218e029ec7d629b0ccbd9b6f 12206 xorg-server_1.20.9-2ubuntu3_source.buildinfo
Files:
 6d5d07c7983346f1da58ae14dc73050a 4563 x11 optional xorg-server_1.20.9-2ubuntu3.dsc
 f8ac64bde1011fbd5cb38c9ad59f39ac 221824 x11 optional xorg-server_1.20.9-2ubuntu3.diff.gz
 3a16ae1fadc058ecba4fe6807cf900bf 12206 x11 optional xorg-server_1.20.9-2ubuntu3_source.buildinfo
Original-Maintainer: Debian X Strike Force <debian-x at lists.debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl/HpVMACgkQZWnYVadE
vpPjRBAAk0nGNc8o/nzUIr1hEIzsMNHgkKEL0joBxTsHO9YRdZ33FdnxZxevm4k7
GDTJOAfDDFS5nZkLnws4wYHpD+rmFlEZPIPhpKZmlkHPhRf+aWpu52LOTN//B3Mc
9UqrZlgsogRIfb9LB+L9U/1Lm+LjwftJLnHd5neaZj78B+8AcudKehHUm9TlsyB/
2msrhMXY/rQwa0FoUoyqjOO+JxIj/NksuN1uZb/zw0EHX4tjBe5Yb58Aj/HbFlxg
RjrRVDLUN5LE0gN/U2zXFLk6ErmmBMjgOPPcZccsH0NzNj11a6wq7J+yh97YPa7I
bk6+pcP5SEvy3GL08z0vIdDnzhYNe7aZ530qCaEeuRnO/OwnYV1qzOAiL42h/Ar7
oBAwHD5g/W0xzNFIJ7Omh9KRokldLlUZ0fGbjl91WPO21cs52tQhblQtpLwU0SOE
PzFME0InAnd5msO1om3NAhCt9zJqJaHvq01+LvRXEWD/GNHaSeDu/UBolyZbH/MR
aIqO7zeBLIAe3gsy3Wo8zId/nRKZkWF4aSGKOx8h1rpjz9RK6DnpeCOtFwWRkslV
WjfLTSJyLVAJGYRFHmgA1nSnuqIs50jWbb5GtJYoICBaIxz2MptxvpcOGEDgSyV/
yu16gGzKgtEvj4rdKJM0BuHSqkdYPjze19zwzcgigmqCOaKhyyY=
=eVDX
-----END PGP SIGNATURE-----


More information about the Hirsute-changes mailing list