-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 04 Apr 2024 11:59:35 +0200 Source: xorg-server Binary: xnest xnest-dbgsym xserver-xephyr xserver-xephyr-dbgsym xserver-xorg-core xserver-xorg-core-dbgsym xserver-xorg-core-udeb xserver-xorg-dev xserver-xorg-legacy xserver-xorg-legacy-dbgsym xvfb xvfb-dbgsym Architecture: amd64 Version: 2:21.1.7-3+deb12u6 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Julien Cristau Description: xnest - Nested X server xserver-xephyr - nested X server xserver-xorg-core - Xorg X server - core server xserver-xorg-core-udeb - Xorg X server - core server (udeb) xserver-xorg-dev - Xorg X server - development files xserver-xorg-legacy - setuid root Xorg server wrapper xvfb - Virtual Framebuffer 'fake' X server Changes: xorg-server (2:21.1.7-3+deb12u6) bookworm-security; urgency=high . * CVE-2024-31080: Heap buffer overread/data leakage in ProcXIGetSelectedEvents * CVE-2024-31081: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice * CVE-2024-31082: Heap buffer overread/data leakage in ProcAppleDRICreatePixmap * CVE-2024-31083: User-after-free in ProcRenderAddGlyphs Checksums-Sha1: efd7bceff5fad5f1f4327b6604d6fbdbe703b931 2681904 xnest-dbgsym_21.1.7-3+deb12u6_amd64.deb da84158bfe1941616a50a42bfb03d3f46b974f23 3013032 xnest_21.1.7-3+deb12u6_amd64.deb 29327c49ac2aeef3217d71661e824051965a6ec1 14688 xorg-server_21.1.7-3+deb12u6_amd64-buildd.buildinfo 656f48512cf831997622391d786e7d672182b5bf 3958600 xserver-xephyr-dbgsym_21.1.7-3+deb12u6_amd64.deb 8755976d8e6c2ef96aaba12860eeffd8aac3bd77 3293224 xserver-xephyr_21.1.7-3+deb12u6_amd64.deb e716d2c0c4c55c89ff5c6cbbbbafcd0578a9694b 5802620 xserver-xorg-core-dbgsym_21.1.7-3+deb12u6_amd64.deb 17cce6ccc89ea0771ba11debf396ef846a06970a 974676 xserver-xorg-core-udeb_21.1.7-3+deb12u6_amd64.udeb c305d5f771e7e9ed344916e2605b23de5ecdfe66 3719856 xserver-xorg-core_21.1.7-3+deb12u6_amd64.deb f408dc66f28ef1bd2b2d8d51de44e32874a7161a 2554088 xserver-xorg-dev_21.1.7-3+deb12u6_amd64.deb 232bd20e6aa40a8454a49b72cdc058f199ad753d 8888 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u6_amd64.deb 9b55351d8d562509e4d7cdb03041a19accae28cd 2388084 xserver-xorg-legacy_21.1.7-3+deb12u6_amd64.deb 71132c4bbdf2e8c08d9de21958d294cacca1a9c2 3270540 xvfb-dbgsym_21.1.7-3+deb12u6_amd64.deb 1b7c13e8c25a07c8519725f7a413f5649524a45c 3151756 xvfb_21.1.7-3+deb12u6_amd64.deb Checksums-Sha256: 843b406d14d01ec32feaf4f1307f7618e1f8018b94641536b681eb138eed5d8b 2681904 xnest-dbgsym_21.1.7-3+deb12u6_amd64.deb 609bfecbcbe866f42f70d5025966743cd7b6192e610728f90a5bf2fec450174a 3013032 xnest_21.1.7-3+deb12u6_amd64.deb 669565b8581cbec8dd5a188e0ffe22e97954e3e15ae8edf45f1ae70b196b7c13 14688 xorg-server_21.1.7-3+deb12u6_amd64-buildd.buildinfo a5be243ce513fbf01fe6517c229e94f2d6c203d6751faf7fc43ab1ccdbfa66f4 3958600 xserver-xephyr-dbgsym_21.1.7-3+deb12u6_amd64.deb 5b9099b581ac653a3f738644ac34f5afc63beec44442e1a464002ce464e695a1 3293224 xserver-xephyr_21.1.7-3+deb12u6_amd64.deb 3f44c0750971e962bc27162a56ea8f63e1b8febbb5a04166e0e80e7c0ef7689a 5802620 xserver-xorg-core-dbgsym_21.1.7-3+deb12u6_amd64.deb 33ee39ba2357c0e082fd5241f23f90a9a289e7bc42e8c6fb9e5c64af071b5f10 974676 xserver-xorg-core-udeb_21.1.7-3+deb12u6_amd64.udeb bcd63d8473f834a044d733e39d8086fe0e6d9aa61e1ee9d4ea3572e41386c63d 3719856 xserver-xorg-core_21.1.7-3+deb12u6_amd64.deb f7a877730ccebb8013b8b59d5606e76761f7ca9bf301aa5e0959a821ce11db56 2554088 xserver-xorg-dev_21.1.7-3+deb12u6_amd64.deb cdbff32b6c67edb307af3538037be3f6c815161a1f3c525d7de2142c1e3f8523 8888 xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u6_amd64.deb 12c278860dceab8d45e09cce68f4d386775e40c690bf04a19c4faf6081ca9357 2388084 xserver-xorg-legacy_21.1.7-3+deb12u6_amd64.deb 105eac701ab4e4355de3f6c4ebc9d1efa569a954c45eeb09ccf59491c5207136 3270540 xvfb-dbgsym_21.1.7-3+deb12u6_amd64.deb 62b60a91b6b2ea4a15edb4ebd8fdd411fd1b0977e61cdd58d3fa71e474a5770f 3151756 xvfb_21.1.7-3+deb12u6_amd64.deb Files: b5e665a55e601fa0f150977a19149e93 2681904 debug optional xnest-dbgsym_21.1.7-3+deb12u6_amd64.deb c91329f2f2c98def2ceaad0ca8980e6f 3013032 x11 optional xnest_21.1.7-3+deb12u6_amd64.deb ec5cb9dd11474dcced13ab68dd364ca2 14688 x11 optional xorg-server_21.1.7-3+deb12u6_amd64-buildd.buildinfo c0045b2494124fd6014909603b6ad4b7 3958600 debug optional xserver-xephyr-dbgsym_21.1.7-3+deb12u6_amd64.deb 6685909c1048a5b409651bd73000602f 3293224 x11 optional xserver-xephyr_21.1.7-3+deb12u6_amd64.deb 59fd99fde67305e9fd998affe7d5784c 5802620 debug optional xserver-xorg-core-dbgsym_21.1.7-3+deb12u6_amd64.deb 4139b847451b2502b5e213dfaa04e470 974676 debian-installer optional xserver-xorg-core-udeb_21.1.7-3+deb12u6_amd64.udeb 34bf1ee39001f0e593aa780740231e81 3719856 x11 optional xserver-xorg-core_21.1.7-3+deb12u6_amd64.deb aa6c281a8d5b3c2b26bf3bce2661ecda 2554088 x11 optional xserver-xorg-dev_21.1.7-3+deb12u6_amd64.deb bc748996ac52afcb18c072c036111dca 8888 debug optional xserver-xorg-legacy-dbgsym_21.1.7-3+deb12u6_amd64.deb 2ed0ec16668918feebef633e53a3f05e 2388084 x11 optional xserver-xorg-legacy_21.1.7-3+deb12u6_amd64.deb a201b2f7d6bd5794a44fab8043c60639 3270540 debug optional xvfb-dbgsym_21.1.7-3+deb12u6_amd64.deb b73ae8e851ba118af3349496ec803289 3151756 x11 optional xvfb_21.1.7-3+deb12u6_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgdRoRGwEM09wlaMzOni7ZmUpKEcFAmYOg5sACgkQOni7ZmUp KEdQJQ/9EyJdPg+OvAUIKc3PKPaTyd6i4JB/bFY7HVjfZTuohrLGddW4HmHgCzHs sDZgK6xegPdQII2K+W1oMFXE9JKVRn4HySRXR7J1Q0bi2ZG9VPqxElmcY5ZeLpT7 dh5NK5cUpxgrrTviVViRI8lBpBIVKHjk8cVtsFQ7YKdVdwtdjDCeLBvUtXP+e09V BH1ic9L9sJDLQ+tsLuzuxNvX1ILcsrL+FShx4smGf9eK+Wy7teP/6Jbfcabfdyw0 /joAAGjC/17iH0vzBenZBjZ6zoXZtzhvQRqqeA8qyhXoBtE7BEdrsf7uLp67/xrr wmG3EWV8bXijmWwDXHx70gYQFaaL0+sTaEBLZmM43ueEgRUo7WZTE2AZXHTHnh2r 8tnsQh+FIlMVkaio+bfhVMJQcrmEL7LAPe/E2uIVBjbsPDBqcfe1V/hqdE+KcYZv WS44wlFI4KdSuGdhTGjWgCKsAuBiZw6I7OhMQS88YDdypB7V7aKNl4fDdFINgxqR U6De+htcQyW41u8VI/K9uK/TfUM+tuTYIoIJ2bH/kuSAF4zkYXeTx0l4KsCCObjN jmlqfs+QdZ11w2kWtSkCHOqi99WvAeqhsEhtwgNl+KCJt9nDGjaaAwHhcD/5lFyN 9H7Vtww+56+GOxtgmIh1AyrzixKFuM3EdTnA6TDGrPvZP605OR4= =FUww -----END PGP SIGNATURE-----