[ubuntu/hardy-security] xorg-server_1.4.1~git20080131-1ubuntu9.3_powerpc_translations.tar.gz, xorg-server, xorg-server_1.4.1~git20080131-1ubuntu9.3_ia64_translations.tar.gz, xorg-server_1.4.1~git20080131-1ubuntu9.3_sparc_translations.tar.gz (delayed), xorg-server_1.4.1~git20080131-1ubuntu9.3_i386_translations.tar.gz, xorg-server_1.4.1~git20080131-1ubuntu9.3_amd64_translations.tar.gz, xorg-server_1.4.1~git20080131-1ubuntu9.3_lpia_translations.tar.gz, xorg-server_1.4.1~git20080131-1ubuntu9.3_hppa_translations.tar.gz 2:1.4.1~git20080131-1ubuntu9.3 (Accepted)

Ubuntu Installer archive at ubuntu.com
Tue May 18 22:04:03 BST 2010


xorg-server (2:1.4.1~git20080131-1ubuntu9.3) hardy-security; urgency=low

  * SECURITY UPDATE: incorrect mod() macro could result in crashes
    caused by remote attackers (LP: #551193).
    - Added debian/patches/xaa-fbcomposite-fix-negative-size.patch
    - CVE-2010-1166
  * SECURITY UPDATE: xvfb MCOOKIE value could be hijacked due to
    visiblity on the command-line,
    - Updated debian/local/xvfb-run from Debian upstream:
      http://git.debian.org/?p=pkg-xorg/xserver/xorg-server.git;a=commitdiff;h=ecf09e571198ee16256a5efd1c23fd286a4f2249;hp=cbccf51785b500f51dc974ed05f5512181d4c51f
    - CVE-2009-1573

Date: Thu, 06 May 2010 13:26:51 -0700
Changed-By: Kees Cook <kees at ubuntu.com>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/hardy/+source/xorg-server/2:1.4.1~git20080131-1ubuntu9.3
-------------- next part --------------
Format: 1.7
Date: Thu, 06 May 2010 13:26:51 -0700
Source: xorg-server
Binary: xserver-xorg-core xserver-xorg-dev xnest xvfb xserver-xephyr xserver-xorg-core-dbg
Architecture: source
Version: 2:1.4.1~git20080131-1ubuntu9.3
Distribution: hardy-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Kees Cook <kees at ubuntu.com>
Description: 
 xnest      - Nested X server
 xserver-xephyr - nested X server
 xserver-xorg-core - Xorg X server - core server
 xserver-xorg-core-dbg - Xorg - the X.Org X server (debugging symbols)
 xserver-xorg-dev - Xorg X server - development files
 xvfb       - Virtual Framebuffer 'fake' X server
Launchpad-Bugs-Fixed: 551193
Changes: 
 xorg-server (2:1.4.1~git20080131-1ubuntu9.3) hardy-security; urgency=low
 .
   * SECURITY UPDATE: incorrect mod() macro could result in crashes
     caused by remote attackers (LP: #551193).
     - Added debian/patches/xaa-fbcomposite-fix-negative-size.patch
     - CVE-2010-1166
   * SECURITY UPDATE: xvfb MCOOKIE value could be hijacked due to
     visiblity on the command-line,
     - Updated debian/local/xvfb-run from Debian upstream:
       http://git.debian.org/?p=pkg-xorg/xserver/xorg-server.git;a=commitdiff;h=ecf09e571198ee16256a5efd1c23fd286a4f2249;hp=cbccf51785b500f51dc974ed05f5512181d4c51f
     - CVE-2009-1573
Files: 
 7718d9ad31ee3b8b5be752f742d3e3d1 2602 x11 optional xorg-server_1.4.1~git20080131-1ubuntu9.3.dsc
 a8c74577a700f9f8040665f46c23e6d8 734709 x11 optional xorg-server_1.4.1~git20080131-1ubuntu9.3.diff.gz
Original-Maintainer: Debian X Strike Force <debian-x at lists.debian.org>


More information about the Hardy-changes mailing list