Package "xorg-server-hwe-16.04"

Name: xorg-server-hwe-16.04


This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Xorg X server - core server
  • Xorg - the X.Org X server (debugging symbols)
  • Xorg X server - development files
  • setuid root Xorg server wrapper

Latest version: 2:1.19.6-1ubuntu4.1~16.04.5
Release: xenial (16.04)
Level: security
Repository: main


Other versions of "xorg-server-hwe-16.04" in Xenial

Repository Area Version
security universe 2:1.19.6-1ubuntu4.1~16.04.5
updates main 2:1.19.6-1ubuntu4.1~16.04.5
updates universe 2:1.19.6-1ubuntu4.1~16.04.5

Packages in group

Deleted packages are displayed in grey.


Version: 2:1.19.3-1ubuntu1~16.04.3 2017-10-12 16:06:50 UTC

  xorg-server-hwe-16.04 (2:1.19.3-1ubuntu1~16.04.3) xenial-security; urgency=medium

  * SECURITY UPDATE: DoS or segment overwrite via shmseg resource id
    - debian/patches/CVE-2017-13721.patch: validate shmseg resource id in
    - CVE-2017-13721
  * SECURITY UPDATE: buffer overflow via XKB data
    - debian/patches/CVE-2017-13723.patch: handle xkb formatted string
      output safely in xkb/xkbtext.c.
    - CVE-2017-13723

 -- Marc Deslauriers <email address hidden> Wed, 11 Oct 2017 13:56:12 -0400

Source diff to previous version
CVE-2017-1372 IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScri

Version: 2:1.18.4-1ubuntu6.1~16.04.2 2017-07-24 18:06:47 UTC

  xorg-server-hwe-16.04 (2:1.18.4-1ubuntu6.1~16.04.2) xenial-security; urgency=medium

  * SECURITY UPDATE: DoS and possible code execution in endianness
    conversion of X Events
    - debian/patches/CVE-2017-10971-1.patch: do not try to swap
      GenericEvent in Xi/sendexev.c.
    - debian/patches/CVE-2017-10971-2.patch: verify all events in
      ProcXSendExtensionEvent in Xi/sendexev.c.
    - debian/patches/CVE-2017-10971-3.patch: disallow GenericEvent in
      SendEvent request in dix/events.c, dix/swapreq.c.
    - CVE-2017-10971
  * SECURITY UPDATE: information leak in XEvent handling
    - debian/patches/CVE-2017-10972.patch: zero target buffer in
      SProcXSendExtensionEvent in Xi/sendexev.c.
    - CVE-2017-10972
    - debian/patches/CVE-2017-2624.patch: use timingsafe_memcmp() in
      configure.ac, include/dix-config.h.in, include/os.h,
      os/mitauth.c, os/timingsafe_memcmp.c.
    - CVE-2017-2624

 -- Marc Deslauriers <email address hidden> Mon, 17 Jul 2017 13:16:04 -0400

CVE-2017-1097 RESERVED
CVE-2017-2624 Timing attack against MIT Cookie

About   -   Send Feedback to @ubuntu_updates