UbuntuUpdates.org

Package "xserver-xephyr"

Name: xserver-xephyr

Description:

nested X server

Latest version: 2:1.18.4-0ubuntu0.11
Release: xenial (16.04)
Level: security
Repository: universe
Head package: xorg-server
Homepage: http://www.x.org/

Links


Download "xserver-xephyr"


Other versions of "xserver-xephyr" in Xenial

Repository Area Version
base universe 2:1.18.3-1ubuntu2
updates universe 2:1.18.4-0ubuntu0.11

Changelog

Version: 2:1.18.4-0ubuntu0.3 2017-07-24 18:06:48 UTC

  xorg-server (2:1.18.4-0ubuntu0.3) xenial-security; urgency=medium

  * SECURITY UPDATE: DoS and possible code execution in endianness
    conversion of X Events
    - debian/patches/CVE-2017-10971-1.patch: do not try to swap
      GenericEvent in Xi/sendexev.c.
    - debian/patches/CVE-2017-10971-2.patch: verify all events in
      ProcXSendExtensionEvent in Xi/sendexev.c.
    - debian/patches/CVE-2017-10971-3.patch: disallow GenericEvent in
      SendEvent request in dix/events.c, dix/swapreq.c.
    - CVE-2017-10971
  * SECURITY UPDATE: information leak in XEvent handling
    - debian/patches/CVE-2017-10972.patch: zero target buffer in
      SProcXSendExtensionEvent in Xi/sendexev.c.
    - CVE-2017-10972
  * SECURITY UPDATE: MIT-MAGIC-COOKIES timing attack
    - debian/patches/CVE-2017-2624.patch: use timingsafe_memcmp() in
      configure.ac, include/dix-config.h.in, include/os.h,
      os/mitauth.c, os/timingsafe_memcmp.c.
    - CVE-2017-2624

 -- Marc Deslauriers <email address hidden> Mon, 17 Jul 2017 09:38:58 -0400

CVE-2017-1097 RESERVED
CVE-2017-2624 Timing attack against MIT Cookie



About   -   Send Feedback to @ubuntu_updates