Format: 1.8 Date: Mon, 17 Jul 2017 13:16:04 -0400 Source: xorg-server-hwe-16.04 Binary: xserver-xorg-core-hwe-16.04 xserver-xorg-dev-hwe-16.04 xserver-xephyr-hwe-16.04 xserver-xorg-core-hwe-16.04-dbg xmir-hwe-16.04 xorg-server-source-hwe-16.04 xwayland-hwe-16.04 xserver-xorg-legacy-hwe-16.04 Architecture: source Version: 2:1.18.4-1ubuntu6.1~16.04.2 Distribution: xenial-security Urgency: medium Maintainer: Ubuntu X-SWAT Changed-By: Marc Deslauriers Description: xmir-hwe-16.04 - Xmir X server xorg-server-source-hwe-16.04 - Xorg X server - source files xserver-xephyr-hwe-16.04 - nested X server xserver-xorg-core-hwe-16.04 - Xorg X server - core server xserver-xorg-core-hwe-16.04-dbg - Xorg - the X.Org X server (debugging symbols) xserver-xorg-dev-hwe-16.04 - Xorg X server - development files xserver-xorg-legacy-hwe-16.04 - setuid root Xorg server wrapper xwayland-hwe-16.04 - Xwayland X server Changes: xorg-server-hwe-16.04 (2:1.18.4-1ubuntu6.1~16.04.2) xenial-security; urgency=medium . * SECURITY UPDATE: DoS and possible code execution in endianness conversion of X Events - debian/patches/CVE-2017-10971-1.patch: do not try to swap GenericEvent in Xi/sendexev.c. - debian/patches/CVE-2017-10971-2.patch: verify all events in ProcXSendExtensionEvent in Xi/sendexev.c. - debian/patches/CVE-2017-10971-3.patch: disallow GenericEvent in SendEvent request in dix/events.c, dix/swapreq.c. - CVE-2017-10971 * SECURITY UPDATE: information leak in XEvent handling - debian/patches/CVE-2017-10972.patch: zero target buffer in SProcXSendExtensionEvent in Xi/sendexev.c. - CVE-2017-10972 * SECURITY UPDATE: MIT-MAGIC-COOKIES timing attack - debian/patches/CVE-2017-2624.patch: use timingsafe_memcmp() in configure.ac, include/dix-config.h.in, include/os.h, os/mitauth.c, os/timingsafe_memcmp.c. - CVE-2017-2624 Checksums-Sha1: 33d3bf9c4cbc3983d30f3c3f3a22698a1734904c 5034 xorg-server-hwe-16.04_1.18.4-1ubuntu6.1~16.04.2.dsc 58abac8ddea54e683726270a60da079abfa3518a 319446 xorg-server-hwe-16.04_1.18.4-1ubuntu6.1~16.04.2.diff.gz Checksums-Sha256: 0d70ad9d318616b074725ad63a9a76998a562a9fa981e25b5e91314773f64f9d 5034 xorg-server-hwe-16.04_1.18.4-1ubuntu6.1~16.04.2.dsc 49298694771d85e95dbb28c0a22815af5294fe0f1294a5f6915a37f4b2f7dc5c 319446 xorg-server-hwe-16.04_1.18.4-1ubuntu6.1~16.04.2.diff.gz Files: 9bdcbe4a77f1800e88b46cbe0beec8c1 5034 x11 optional xorg-server-hwe-16.04_1.18.4-1ubuntu6.1~16.04.2.dsc 5d8310c3d809a18f085e7590ac9eef0d 319446 x11 optional xorg-server-hwe-16.04_1.18.4-1ubuntu6.1~16.04.2.diff.gz Original-Maintainer: Debian X Strike Force