[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20170709204215.ngfy5c3pxjxfmy5k@pisco.westfalen.local>
Date: Sun, 9 Jul 2017 22:42:15 +0200
From: Moritz Muehlenhoff <jmm@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 3905-1] xorg-server security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------------
Debian Security Advisory DSA-3905-1 security@...ian.org
https://www.debian.org/security/ Moritz Muehlenhoff
July 09, 2017 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : xorg-server
CVE ID : CVE-2017-10971 CVE-2017-10972
Debian Bug : 867492
Two security issues have been discovered in the X.org X server, which
may lead to privilege escalation or an information leak.
For the oldstable distribution (jessie), these problems have been fixed
in version 2:1.16.4-1+deb8u1.
For the stable distribution (stretch), these problems have been fixed in
version 2:1.19.2-1+deb9u1. Setups running root-less X are not affected.
For the testing distribution (buster), these problems have been fixed
in version 2:1.19.3-2.
For the unstable distribution (sid), these problems have been fixed in
version 2:1.19.3-2.
We recommend that you upgrade your xorg-server packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAllilJAACgkQEMKTtsN8
TjYfGxAAj4PL+dnOX0CNbm+NJ/hW5nw0xwCrDiN8QzCJf/CDaPym+MhdB4wSEeJw
pTCDxqTrt2cqAtOAIRexpq8Hx64L0nW2kuBriaQHpRronULyrVZiCheeIlyIEP4P
lHeH2WtzPuY++yRq3NauM/ylnDzjFBaMCaIO4yUNetJ8+j8bpaGeW7/KOhTqTfab
e+WQLcRaWO+Ple3A5YXHZWRvebeaPtL539oucdx7IBOIuXIGqH6FZ9RcH0c8GTQN
qjaPNDeeU5VK93i0D93yoBVT9VpDI3B9SoPghsCmRsDDUZ9I9/xelzoKDdtClRmW
9X9QyOSpD8Qp5umad78Bqin02A5F4lLOYtPHCv0dokICP7tmRE/6Rxu3qvjnt4n7
689yeidSUqZ9Z350bDz/rafRCcz5u/hon3QnUChl6MBFTkSYpPMOfMwpGz4DN5Hg
egqmV6qDRtCp1nSnOHThBzKQnRIn5JZdyiZ0na5bVsMYvp26IP+2yZO/2P8d+zOn
Crd/TLxI9C04+1mfEH14rT84FUvO76FBUfyd1q4Urb7/laMJ/HtkC3MPQ4Diaqmo
lQ4w+yeKf3/XoKZii6fz/sMNc73XDV6fleT1/9FsjbXaa1CD5ZOvYRcVPs3sYpAu
ZKp5L1vlSuzLDd2jCDYvRRKRBQFvQ3aXiL8zbdrdzQipx5pPufk=
=a7RZ
-----END PGP SIGNATURE-----
Powered by blists - more mailing lists