-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 17 Dec 2022 11:00:08 +0100 Source: xorg-server Binary: xdmx xdmx-dbgsym xdmx-tools xdmx-tools-dbgsym xnest xnest-dbgsym xserver-xephyr xserver-xephyr-dbgsym xserver-xorg-core xserver-xorg-core-dbgsym xserver-xorg-core-udeb xserver-xorg-dev xserver-xorg-legacy xserver-xorg-legacy-dbgsym xvfb xvfb-dbgsym xwayland xwayland-dbgsym Architecture: amd64 Version: 2:1.20.11-1+deb11u4 Distribution: bullseye-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Salvatore Bonaccorso Description: xdmx - distributed multihead X server xdmx-tools - Distributed Multihead X tools xnest - Nested X server xserver-xephyr - nested X server xserver-xorg-core - Xorg X server - core server xserver-xorg-core-udeb - Xorg X server - core server (udeb) xserver-xorg-dev - Xorg X server - development files xserver-xorg-legacy - setuid root Xorg server wrapper xvfb - Virtual Framebuffer 'fake' X server xwayland - Xwayland X server Closes: 1026071 Changes: xorg-server (2:1.20.11-1+deb11u4) bullseye-security; urgency=high . * Non-maintainer upload by the Security Team. * Xtest: disallow GenericEvents in XTestSwapFakeInput (CVE-2022-46340) (Closes: #1026071) * Xi: disallow passive grabs with a detail > 255 (CVE-2022-46341) (Closes: #1026071) * Xext: free the XvRTVideoNotify when turning off from the same client (CVE-2022-46342) (Closes: #1026071) * Xext: free the screen saver resource when replacing it (CVE-2022-46343) (Closes: #1026071) * Xi: return an error from XI property changes if verification failed * Xi: avoid integer truncation in length check of ProcXIChangeProperty (CVE-2022-46344) (Closes: #1026071) * xkb: reset the radio_groups pointer to NULL after freeing it (CVE-2022-4283) (Closes: #1026071) Checksums-Sha1: 26c2277f2bfc6bce61a5cd4899ca49a87bec9b05 3122084 xdmx-dbgsym_1.20.11-1+deb11u4_amd64.deb 725fe7915879befa1c0d3614cd9b613b77238d70 201456 xdmx-tools-dbgsym_1.20.11-1+deb11u4_amd64.deb ba31c030f351316dbe09e1e117697a20b4d78b27 2316380 xdmx-tools_1.20.11-1+deb11u4_amd64.deb e4799dabea0a325b7cf92389ce2922b5efa6938f 3023932 xdmx_1.20.11-1+deb11u4_amd64.deb b55dc08664792d1fcd1046a6c0c35d13adff03ff 2660936 xnest-dbgsym_1.20.11-1+deb11u4_amd64.deb 60bc0b4f32a0779440e35c148ce721ee2106290a 2908692 xnest_1.20.11-1+deb11u4_amd64.deb 712359fa94538e1c01bc5a9c6231c10ecd502b65 16752 xorg-server_1.20.11-1+deb11u4_amd64-buildd.buildinfo cd027b6c6946ab5e9949433a8ed5b97f63f585c9 3896216 xserver-xephyr-dbgsym_1.20.11-1+deb11u4_amd64.deb 17838ca3bb2a93084302673915ace00facc4ccc9 3180020 xserver-xephyr_1.20.11-1+deb11u4_amd64.deb 4cea4885e112c5657bddb694ac3a1c740f228b46 5630312 xserver-xorg-core-dbgsym_1.20.11-1+deb11u4_amd64.deb ae57805e9ab30da18b1928e5d11ab48de365c868 947332 xserver-xorg-core-udeb_1.20.11-1+deb11u4_amd64.udeb 95c9552c1db62033a1f04226d61da4cdf257a88a 3603164 xserver-xorg-core_1.20.11-1+deb11u4_amd64.deb 38c52511d94644fc05d54b6c93b53dbd1ac11983 2457868 xserver-xorg-dev_1.20.11-1+deb11u4_amd64.deb a90e194008558592ad499b6a3c7bf9dce6516ee1 8808 xserver-xorg-legacy-dbgsym_1.20.11-1+deb11u4_amd64.deb 7c356706dd698f46e596f14341a78721f93760fc 2289248 xserver-xorg-legacy_1.20.11-1+deb11u4_amd64.deb 1704ba3ceca1f3e7f8d35d3dba620f55c2f6ac7a 3245064 xvfb-dbgsym_1.20.11-1+deb11u4_amd64.deb ef856d28af0a559f122c8d0a0fe9e450d428f536 3043464 xvfb_1.20.11-1+deb11u4_amd64.deb 2022b3ea2a66bdd7d623819c01b37cf1a62b2f7f 3682100 xwayland-dbgsym_1.20.11-1+deb11u4_amd64.deb b3fadadde82ae93f8ebcaadae3232bcb3093fe41 3132568 xwayland_1.20.11-1+deb11u4_amd64.deb Checksums-Sha256: 12b450ac6282bea4f09a00528a09193563ca628eacd4975bcf415096c2d93b35 3122084 xdmx-dbgsym_1.20.11-1+deb11u4_amd64.deb a681d6567e5c6b4a7956ef303d3987d9708bc93b833a831a66545d6552c4b4a0 201456 xdmx-tools-dbgsym_1.20.11-1+deb11u4_amd64.deb cde4220142f9296f4d609b1c625570af26d4ad5810e7e28a2c239a76d327c329 2316380 xdmx-tools_1.20.11-1+deb11u4_amd64.deb 5dd00843a2e0f5b6624eb8f28cb89cfbb2534ed020f76475f73608dd04de51f7 3023932 xdmx_1.20.11-1+deb11u4_amd64.deb cea199bca87ddb89d5b90a3178d8fd9a2853f8ac8498c736a8b0a4b30a93e97e 2660936 xnest-dbgsym_1.20.11-1+deb11u4_amd64.deb 2da43123ba7cedb0c748a9657b5065020143061ea9e2bed093d1e7d5d75f0bab 2908692 xnest_1.20.11-1+deb11u4_amd64.deb 7ce7682d95ef92508875355b42b44ce3dd175686b5c508fb256dd54f321afd0f 16752 xorg-server_1.20.11-1+deb11u4_amd64-buildd.buildinfo f48451f17a37d352807ce3b6c546cf3c336f496ffa44fc4f404fcf5ee5c2a206 3896216 xserver-xephyr-dbgsym_1.20.11-1+deb11u4_amd64.deb 103470ada0729bfbf4329637f701220fb5a456626f492df354b53e0e2a68187b 3180020 xserver-xephyr_1.20.11-1+deb11u4_amd64.deb bded1af95c307300c3400a66841d54c5a8a20454f536ccd3a7a29989f76806b1 5630312 xserver-xorg-core-dbgsym_1.20.11-1+deb11u4_amd64.deb 7321ab68bb2774d69b5a812a24c47a09d299a0d8daf1ad5f7c70f445c51052ec 947332 xserver-xorg-core-udeb_1.20.11-1+deb11u4_amd64.udeb 7e8fd7dfaed6bc4acfcf92e6593d39579a2470bb5303aa3dbeaa5c9b8976a9f7 3603164 xserver-xorg-core_1.20.11-1+deb11u4_amd64.deb f1b588080c4ff3a4bdb5eb0d03b4eec7e091c4da8bc9de95952e21783d4af7cb 2457868 xserver-xorg-dev_1.20.11-1+deb11u4_amd64.deb 02c1ae506dac0e1408bd906afc31b783865aa996a0aa7c755ab7ae2ea7cdb500 8808 xserver-xorg-legacy-dbgsym_1.20.11-1+deb11u4_amd64.deb 013ed6de50b38ee4a56c467a0889df3a2e3a928eb0c5347815e6a2bf730aaaf2 2289248 xserver-xorg-legacy_1.20.11-1+deb11u4_amd64.deb 9b6ea80be580667e32bcef9869a30c65c641d2457b056cfcb63e4329162829eb 3245064 xvfb-dbgsym_1.20.11-1+deb11u4_amd64.deb 48069d1616abc16f69dadae782f400181bbfa65eb515b51f0bd7586d3d0cd12f 3043464 xvfb_1.20.11-1+deb11u4_amd64.deb 6308bf386db4f51748f7424478f5b01cc380cb57e910cf7dbfcd5aa0e9628a64 3682100 xwayland-dbgsym_1.20.11-1+deb11u4_amd64.deb c200e3f681c6bab7263b0ddd159e3b3352fc58258c223c6a3649187827ecc298 3132568 xwayland_1.20.11-1+deb11u4_amd64.deb Files: a4a1d7ea0b7ef72952b18daf0f11a31c 3122084 debug optional xdmx-dbgsym_1.20.11-1+deb11u4_amd64.deb 2bd50dbb13e277bcae495b75c32bd711 201456 debug optional xdmx-tools-dbgsym_1.20.11-1+deb11u4_amd64.deb 19684fdc43a12c70d0d7b4968a8ebc81 2316380 x11 optional xdmx-tools_1.20.11-1+deb11u4_amd64.deb 773c142ff06c9b03622fc117296b5477 3023932 x11 optional xdmx_1.20.11-1+deb11u4_amd64.deb dafedb2f7d73db8b34e71c74acd3d6fa 2660936 debug optional xnest-dbgsym_1.20.11-1+deb11u4_amd64.deb f57ce1338abd23197660cfcf9ba7668b 2908692 x11 optional xnest_1.20.11-1+deb11u4_amd64.deb 7279468bc6e3f9fed2eedb9d5073c4d6 16752 x11 optional xorg-server_1.20.11-1+deb11u4_amd64-buildd.buildinfo 278ec5864c9191acb34f5209d5540f06 3896216 debug optional xserver-xephyr-dbgsym_1.20.11-1+deb11u4_amd64.deb a5cd96f11635fa55f9f673bd4fb9d461 3180020 x11 optional xserver-xephyr_1.20.11-1+deb11u4_amd64.deb 0cd286476470d61926cb26a69f855827 5630312 debug optional xserver-xorg-core-dbgsym_1.20.11-1+deb11u4_amd64.deb fc9bec5af51f8e41bae971eacf67dc58 947332 debian-installer optional xserver-xorg-core-udeb_1.20.11-1+deb11u4_amd64.udeb 95f4b4852701329d62281d74aeefe1f6 3603164 x11 optional xserver-xorg-core_1.20.11-1+deb11u4_amd64.deb 26d3985a732a9134a75cf47df44b6f4e 2457868 x11 optional xserver-xorg-dev_1.20.11-1+deb11u4_amd64.deb 32c6639a800214bc8153c76b405964a4 8808 debug optional xserver-xorg-legacy-dbgsym_1.20.11-1+deb11u4_amd64.deb 7c67ed00fd322594626a6d0843d65630 2289248 x11 optional xserver-xorg-legacy_1.20.11-1+deb11u4_amd64.deb b52c957913223ebad1e37fb3922acea7 3245064 debug optional xvfb-dbgsym_1.20.11-1+deb11u4_amd64.deb befbeb848b0a8c4be99c02a05389edf2 3043464 x11 optional xvfb_1.20.11-1+deb11u4_amd64.deb cf6ee841ac718b1a0bfcaaa5238e77ad 3682100 debug optional xwayland-dbgsym_1.20.11-1+deb11u4_amd64.deb 53b765a59ef234f8a195a630b83ff863 3132568 x11 optional xwayland_1.20.11-1+deb11u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHWxRmfLuR591d5l2LWlxuzKfiVUFAmOdotMACgkQLWlxuzKf iVWDsRAAna6s7kjYEQJG1Al7wLQwipRePgMOeMast/nZKhRARtbKeHGTNMAKAsb9 3PKtkQ9OvaB+v7u9J2e8h9CKgX7Wnzvu3SASz1m2mitH9C4HPNVMXKa4hDbZkTLi ZRsbh+TrDrMOjRE1yXJZBYOgiI2468jxBPBSsuOKCaYZ2ber28wYJ4e5mZwY0fg0 vEPXTMNr7dbOfVXmamHCo3O37nk0WQy4uIV2RonV6jt0+PB126dn8Vgy8bZZoGHu BX+ivD800mLqVB2H6qSozWQzmW0Z6naruzj3DMnVD9ZCE4r+nN1RhkAnL9FjDz71 UiEhNIMCduAQpbqTcZg88BI8dU5afcjz/LHtvHxsa9h9HjL5KBmCY8aCDDbgbKoI Zfy9e41edNIq6SFGvRW/1hGI9CpiZEj8TM2rZ7ZtXTS8DeMeYiknwDovBnqvJYIs X+d4a2nXkk48qOzpYoUMCFTNdEgCQHp5sZxGDhkPKCoG3U0BQLYMjzOAapR+3t1k Rg+Y4O+PLtioPxid2dxdj8ilsHSEGlNtnhHF6W8XGlRCOQMz6tHUupR27gb0g6pD me0v0dz1fDztJCz/TnHb6DmCFTM7HKW3OReZB8bnVAISpzuAZvkiRIBvDb9smqD9 pYuE0shbnlvUjO+pwsVTaKtKeRvYFyHeTcLgpWF/8RrDas5+XJc= =CcJo -----END PGP SIGNATURE-----