-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 17 Dec 2023 13:03:02 +0100 Source: xorg-server Architecture: source Version: 2:1.20.4-1+deb10u12 Distribution: buster-security Urgency: high Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Changes: xorg-server (2:1.20.4-1+deb10u12) buster-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2023-6377 Sync "Xi: allocate enough XkbActions for our buttons" The original upstream patch applied for CVE-2023-6377 was incomplete and still allows OOM access. This update syncs the patch with the upstream applied patch. Checksums-Sha1: 01ca32ec9620062cfba8e8e87e98872d2ed65116 4345 xorg-server_1.20.4-1+deb10u12.dsc 94dd9612c5e4233ed3cb23063ab10f43b4ae4bb2 8553791 xorg-server_1.20.4.orig.tar.gz de105211c08161d5b0bd319b6ca2c6beb45c2aa3 165144 xorg-server_1.20.4-1+deb10u12.diff.gz dc5dadece7d72ee97afe3b9799b16714a3c6343b 17779 xorg-server_1.20.4-1+deb10u12_amd64.buildinfo Checksums-Sha256: c00115b80d7229de600b0bab4fefb5ba8c82617b6aec035dd976a6c4e9c33b76 4345 xorg-server_1.20.4-1+deb10u12.dsc a6447de89eca3e22eeead682b325d902779569534ad83388c9e16611d72baaf3 8553791 xorg-server_1.20.4.orig.tar.gz a36e3a1cf7a6b3c1c71c0480fe9bbe3728e6eb50c94e1b695e3b7d58f61d25fe 165144 xorg-server_1.20.4-1+deb10u12.diff.gz 04ffe901661ca98fdda05835d3f58e2c85b09078ca636de97ce7427aa0287e97 17779 xorg-server_1.20.4-1+deb10u12_amd64.buildinfo Files: 506fbf36a59962349c72e52b88a080fc 4345 x11 optional xorg-server_1.20.4-1+deb10u12.dsc 4151b46d6036f4997d27c2d2b7be38e7 8553791 x11 optional xorg-server_1.20.4.orig.tar.gz 63e99689df729f1e54dcdd07c709b468 165144 x11 optional xorg-server_1.20.4-1+deb10u12.diff.gz 723559a253e49285447c4dcecf74d343 17779 x11 optional xorg-server_1.20.4-1+deb10u12_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmV+/xRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYRynTD/wNrkouBuWsVqWxQ7LHC2whDliLjzLv I5/f2yeNBRzXZIt1rmIFf/PVFDva/TChMOUuhXZyBMy14Sp2ltAWEwGIdbVHL3Ir J1JB5PVxgUR66WbTGhRxx22BFgZhAH66X/2cXQ/ffNia+p2Kx3K5FzmPq98zfIac cobIzfL+P12Dod2HLNZpFZTR0zgfO+Tawp+l2ftr2sh54nAp6OAclnQqPbW+foQr NiL/Msz6qv/1jsRzI7wd2IY7rmktIW4AwWnuXOx6G4yP9pVh0OGm8W3caJWWwmz4 XM0Z8vSDMUQu/cvD/P2DGBIgU+pH990mSlaV33X34pbwrT0LnFdBQQuNtEi7FR/t 19gjd7xXtD6qtCB4lw70dtXhfAz8FBjnW9nIjuvPn2FLpuQ5nWo4GCfgpjYj4ZGe A8i5gl7oW/Lg1FFHtUmHMAA3azXgyCSdhp4gFVujUHUb6yVW/AOwXud6FUhAwAlv K/5u7eQ+5yiPJHRGn0Zpcf5Q/3pgIciYCYSvrvXBewwgm9l0n/CRxIIUgkdCMp09 kJ2gVbHQmv97e73ZjtjA9lpTefCqWI38v1VWmv7ZcNGiuSKBa4pCT7WFKTsZA2kQ dWzuZJfcKUwS4oguECb9PV9zGgOlBM7d3NHZ0MoOrf2t10cqKKUMnQCFbEVGHBkn 2F4zqKUZRTLFzg== =F6+w -----END PGP SIGNATURE-----