-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 29 May 2013 11:15:36 +0200 Source: libxxf86vm Binary: libxxf86vm1 libxxf86vm1-dbg libxxf86vm-dev Architecture: source amd64 Version: 1:1.1.0-2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Julien Cristau <jcristau@debian.org> Description: libxxf86vm-dev - X11 XFree86 video mode extension library (development headers) libxxf86vm1 - X11 XFree86 video mode extension library libxxf86vm1-dbg - X11 XFree86 video mode extension library (debug package) Changes: libxxf86vm (1:1.1.0-2+squeeze1) squeeze-security; urgency=high . * When Xcalloc() returns NULL, you don't need to Xfree() it * Improve error handling in XF86VidModeGetMonitor() * Unlock display before returning alloc error in XF86VidModeGetModeLine(), XF86VidModeGetAllModeLines(), XF86VidModeGetDotClocks() * memory corruption in XF86VidModeGetGammaRamp() [CVE-2013-2001] * avoid integer overflow in XF86VidModeGetModeLine Checksums-Sha1: ee3aa811f39871c88b7f2d43fce22093f8259ef9 2104 libxxf86vm_1.1.0-2+squeeze1.dsc 0eb17331f21bd9f4bf896a4a25c61465bd690598 300276 libxxf86vm_1.1.0.orig.tar.gz 4919a03286a1c0a39cebc5b2b6335639abe141ae 16775 libxxf86vm_1.1.0-2+squeeze1.diff.gz c4b23ad38b9ea4e8030bac44323f50d63563d5b6 15762 libxxf86vm1_1.1.0-2+squeeze1_amd64.deb 3cb86267cf8ca63fa3952988691bcf34ddb4eb4d 32950 libxxf86vm1-dbg_1.1.0-2+squeeze1_amd64.deb 2af0ddb3b9237d6c5098b0b23e0fc341754bb340 21766 libxxf86vm-dev_1.1.0-2+squeeze1_amd64.deb Checksums-Sha256: 76e28ad261842bbd33972001e1d9f17d280d5e8e13dcca83e5ab7ad6e5ea199d 2104 libxxf86vm_1.1.0-2+squeeze1.dsc bb8435887360a252db7af9f9a0f511850fe916d7da3256279568d4ec794cf787 300276 libxxf86vm_1.1.0.orig.tar.gz 6fe10fa253fd39b9f6f619237d7937d39b3723b52ecc34894b4f0c76a29414dd 16775 libxxf86vm_1.1.0-2+squeeze1.diff.gz cbfe9fd023877769215f4e3c5d70316d6f292d9ef73c7b4164c0430bb18ef9cb 15762 libxxf86vm1_1.1.0-2+squeeze1_amd64.deb 5d82f541280dbea5fd38081e6444aab596b65dc83b2bf9248ea38c949e241fc0 32950 libxxf86vm1-dbg_1.1.0-2+squeeze1_amd64.deb 9c912308766f9a708d994cec17bdfb5a3146dd59e99c493f27d303f862555902 21766 libxxf86vm-dev_1.1.0-2+squeeze1_amd64.deb Files: 057b89125a2421cd7b21ecde6b223982 2104 x11 optional libxxf86vm_1.1.0-2+squeeze1.dsc 52b49483eccbdd1566b8c560fe7f76e8 300276 x11 optional libxxf86vm_1.1.0.orig.tar.gz 928f7df7ebee9554855261d2cc68e9a2 16775 x11 optional libxxf86vm_1.1.0-2+squeeze1.diff.gz c01fe063ef51e8c9af141ca21109b485 15762 libs optional libxxf86vm1_1.1.0-2+squeeze1_amd64.deb 761866bfda6a435dace4406a13328908 32950 debug extra libxxf86vm1-dbg_1.1.0-2+squeeze1_amd64.deb 7da735308aa6b280fa25c99770b7e7c0 21766 libdevel optional libxxf86vm-dev_1.1.0-2+squeeze1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJRpxiLAAoJEDEBgAUJBeQMnbIQANFEIcrMEWBVuRxa1WWE0Rwx McqJlFLvU7L86guT8+v3g3sBlOoIMg80aA9hYdjH/qxQSYPm8W8xwwfiPnd5F9za cD05W5Qs4r1gVGCtoYtvUI/+qDTTxUWF5G6P65bztdpAxRKO7ERP32rzc2Y+D6IH K10OgPgu0/irvhKNQktseFMPpEYW6/hJw+pfFxdZxkeCiIamtKG2pEtDa9VoW+51 wOAy9be6ttzlcAbVTMx9+hV+Da7L4Pw8H+o9lCJyzI65SVqROHTGFEcvaoMrswJs csnOOHI95Mym2l1CmeTPotUPvrdUm93OmlhuQwvIPMkwZAqjjCj/j904NuwzyGc/ tyGdtYNobt/VKxlDyXbx2Ir/d6qWc5TUfxiEm6i6FRhtavnGDXefGZiHVCOmoYUl LNKMsww/JkD+FiU4xdVOFsEqi9JIFa6FAzbQtBYaMfiyfZWsDooSMftbIoz0PwBW 5dYOJxH0q5Nm4k2tvMXTywaBFM1qLDIDDjQF2GApkYy2Hyqt//IyAd5Jbglq8MeJ ZiRaLaQ/Oka5o9Hvj59PU+56SluI2nc0WqrUc9gYPO3d3zSIphQdDSG+V3x705EH MnEndlSL/dcb7OKqycRd77CN7mklwLI8j/a58eoTTz5+Gb8n7ecpL9YsSYBkoLQ0 CYixUR2Rq4blS5XREP8w =Grrb -----END PGP SIGNATURE-----