-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 27 Aug 2020 10:51:48 +0200 Source: xorg-server Architecture: source Version: 2:1.20.4-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 968986 Changes: xorg-server (2:1.20.4-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix for ZDI-11426 (CVE-2020-14347) (Closes: #968986) * Correct bounds checking in XkbSetNames() (CVE-2020-14345) * Fix XIChangeHierarchy() integer underflow (CVE-2020-14346) * Fix XkbSelectEvents() integer underflow (CVE-2020-14361) * Fix XRecordRegisterClients() Integer underflow (CVE-2020-14362) Package-Type: udeb Checksums-Sha1: a0c47587fc711a9040a7e614c07873943144315d 4337 xorg-server_1.20.4-1+deb10u1.dsc 94dd9612c5e4233ed3cb23063ab10f43b4ae4bb2 8553791 xorg-server_1.20.4.orig.tar.gz 0378b1b847c504b1164e5da94c36368f48a9a760 147972 xorg-server_1.20.4-1+deb10u1.diff.gz Checksums-Sha256: e5a7140cbb0e3b2a98e7faae254356c5dfe5c0cdf0a81df9b55148efcb82788e 4337 xorg-server_1.20.4-1+deb10u1.dsc a6447de89eca3e22eeead682b325d902779569534ad83388c9e16611d72baaf3 8553791 xorg-server_1.20.4.orig.tar.gz 50a72b996315a618ffae32df71eef4bb2973a72a788835af95b1d7f99a045732 147972 xorg-server_1.20.4-1+deb10u1.diff.gz Files: 49362dcbc35d3ca8117e9680d8f50685 4337 x11 optional xorg-server_1.20.4-1+deb10u1.dsc 4151b46d6036f4997d27c2d2b7be38e7 8553791 x11 optional xorg-server_1.20.4.orig.tar.gz 45bf79942eb911cc8f87861ba1297010 147972 x11 optional xorg-server_1.20.4-1+deb10u1.diff.gz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl9IjqFfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EuRMQAJ5d0EAvj9ZDYko+du1lfCcC2zkYsbDA flINzz7hJpPdOB/jwlRZWA3msQhrUqFDwIUWrSEs2xn0C+KVo8iwhGz7zJRKuv3O iqa79jVfJQuUKYdkEjMAbgM+fE9ARxgyRbvqL20gnMIFk6nprq3RnZWMH/ScG68Y aRON5jFM6oPFNFcmcJ8tIdc0jpYloUYQhhNKjJAJNmLBrGksvd1eW3Hbp0X4yRnX fXCBNJFcJfq6pQDaBQJzNoQazA47j7MO+Ci/hMta427lB+DU49WnS07CX1E58Oia fVEnJtp66O2J9J651Vw2/VjBKz0lQ+4hDmcocqbjFRltPdyXFDRItkG8fyZN/RHl g9+isMQ7SxL9uoWzCbfjI9SsKzYLy8x5QXbHi+zD8QX11m1TOGmct8OgxGZqZH6p HmEoxYfdoFyYD6DGZIsqt9KVb2l8rzA0bijru43JjJ0YUi27bK3LmPpClbcWAmkU tj0BfhVQ/cd7TrpcU+DyiDHZ4JTt+GTQNqeeZwJtpBa9uhW9792WtAsxfD7iZ+Sn tf8nlRt/PVQ+9WrYme2/lB2DARWBrngLHvOaIQKUAzxOCNd8HS0qm/S25Wxdy9IF VvRo5DJ0mhueuaedZWLle4LLymcPTWLmaEb25Ie0TFutU82gjpPOxlSh+nF24HS1 F+xuitU2mzgD =QqOB -----END PGP SIGNATURE-----