• [SECURITY] [DSA 3905-1] xorg-server security update

    From Moritz Muehlenhoff@1:229/2 to All on Sun Jul 9 22:50:01 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3905-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    July 09, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : xorg-server
    CVE ID : CVE-2017-10971 CVE-2017-10972
    Debian Bug : 867492

    Two security issues have been discovered in the X.org X server, which
    may lead to privilege escalation or an information leak.

    For the oldstable distribution (jessie), these problems have been fixed
    in version 2:1.16.4-1+deb8u1.

    For the stable distribution (stretch), these problems have been fixed in version 2:1.19.2-1+deb9u1. Setups running root-less X are not affected.

    For the testing distribution (buster), these problems have been fixed
    in version 2:1.19.3-2.

    For the unstable distribution (sid), these problems have been fixed in
    version 2:1.19.3-2.

    We recommend that you upgrade your xorg-server packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAllilJAACgkQEMKTtsN8 TjYfGxAAj4PL+dnOX0CNbm+NJ/hW5nw0xwCrDiN8QzCJf/CDaPym+MhdB4wSEeJw pTCDxqTrt2cqAtOAIRexpq8Hx64L0nW2kuBriaQHpRronULyrVZiCheeIlyIEP4P lHeH2WtzPuY++yRq3NauM/ylnDzjFBaMCaIO4yUNetJ8+j8bpaGeW7/KOhTqTfab e+WQLcRaWO+Ple3A5YXHZWRvebeaPtL539oucdx7IBOIuXIGqH6FZ9RcH0c8GTQN qjaPNDeeU5VK93i0D93yoBVT9VpDI3B9SoPghsCmRsDDUZ9I9/xelzoKDdtClRmW 9X9QyOSpD8Qp5umad78Bqin02A5F4lLOYtPHCv0dokICP7tmRE/6Rxu3qvjnt4n7 689yeidSUqZ9Z350bDz/rafRCcz5u/hon3QnUChl6MBFTkSYpPMOfMwpGz4DN5Hg egqmV6qDRtCp1nSnOHThBzKQnRIn5JZdyiZ0na5bVsMYvp26IP+2yZO/2P8d+zOn Crd/TLxI9C04+1mfEH14rT84FUvO76FBUfyd1q4Urb7/laMJ/HtkC3MPQ4Diaqmo lQ4w+yeKf3/XoKZii6fz/sMNc73XDV6fleT1/9FsjbXaa1CD5ZOvYRcVPs3sYpAu ZKp5L1vlSuzLDd2jCDYvRRKRBQFvQ3aXiL8zbdrdzQipx5pPufk=
    =a7RZ
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)