xorg/xorg-server/.signature
Fredrik Rinnestam d139c53819 [notify] xorg-server: 1.20.10. Fixes for CVE-2020-14360, CVE-2020-25712
Multiple input validation failures in X server XKB extension
============================================================

These issues can lead to privileges elevations for authorized clients
on systems where the X server is running privileged.

* CVE-2020-14360 / ZDI CAN 11572 XkbSetMap Out-Of-Bounds Access

Insufficient checks on the lengths of the XkbSetMap request can lead to
out of bounds memory accesses in the X server.

* CVE-2020-25712 / ZDI-CAN-11839 XkbSetDeviceInfo Heap-based Buffer Overflow

Insufficient checks on input of the XkbSetDeviceInfo request can lead
to a buffer overflow on the head in the X server.
2020-12-01 19:02:53 +01:00

6 lines
427 B
Plaintext

untrusted comment: verify with /etc/ports/xorg.pub
RWTSGWF5Q7TndGMXoWb+WtrcCadowj6ixbUkX1TOFZ+ysPp8DAjN6UvkF+9DZlb3fulCIF8Oe3YAI+gG02W3ayt3glv/hreengk=
SHA256 (Pkgfile) = ed42a86d4d3166f51df11f3e82373fd8e52a10056620a818986e19a45d870083
SHA256 (.footprint) = d159a275a4868001332954580ab4f70976c97a80334b157023935b36722e50cd
SHA256 (xorg-server-1.20.10.tar.bz2) = 977420c082450dc808de301ef56af4856d653eea71519a973c3490a780cb7c99