[ubuntu/natty-security] xorg-server 2:1.10.1-1ubuntu1.3 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Oct 18 16:04:20 UTC 2011


xorg-server (2:1.10.1-1ubuntu1.3) natty-security; urgency=low

  * SECURITY UPDATE: file existence disclosure
    - debian/patches/505_CVE-2011-4028.patch: open lockfile with O_NOFOLLOW
      in os/utils.c.
    - CVE-2011-4028
  * SECURITY UPDATE: privilege escalation via file permission change
    - debian/patches/506_CVE-2011-4029.patch: use fchmod to prevent race
      in os/utils.c.
    - CVE-2011-4029

Date: Thu, 13 Oct 2011 11:03:44 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu X-SWAT <ubuntu-x at lists.ubuntu.com>
https://launchpad.net/ubuntu/natty/+source/xorg-server/2:1.10.1-1ubuntu1.3
-------------- next part --------------
Format: 1.8
Date: Thu, 13 Oct 2011 11:03:44 -0400
Source: xorg-server
Binary: xserver-xorg-core xserver-xorg-core-udeb xserver-xorg-dev xdmx xdmx-tools xnest xvfb xserver-xephyr xserver-xfbdev xserver-xorg-core-dbg xserver-common
Architecture: source
Version: 2:1.10.1-1ubuntu1.3
Distribution: natty-security
Urgency: low
Maintainer: Ubuntu X-SWAT <ubuntu-x at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 xdmx       - distributed multihead X server
 xdmx-tools - Distributed Multihead X tools
 xnest      - Nested X server
 xserver-common - common files used by various X servers
 xserver-xephyr - nested X server
 xserver-xfbdev - Linux framebuffer device tiny X server
 xserver-xorg-core - Xorg X server - core server
 xserver-xorg-core-dbg - Xorg - the X.Org X server (debugging symbols)
 xserver-xorg-core-udeb - Xorg X server - core server (udeb)
 xserver-xorg-dev - Xorg X server - development files
 xvfb       - Virtual Framebuffer 'fake' X server
Changes: 
 xorg-server (2:1.10.1-1ubuntu1.3) natty-security; urgency=low
 .
   * SECURITY UPDATE: file existence disclosure
     - debian/patches/505_CVE-2011-4028.patch: open lockfile with O_NOFOLLOW
       in os/utils.c.
     - CVE-2011-4028
   * SECURITY UPDATE: privilege escalation via file permission change
     - debian/patches/506_CVE-2011-4029.patch: use fchmod to prevent race
       in os/utils.c.
     - CVE-2011-4029
Checksums-Sha1: 
 0bc23adff57b309931c6224de31bb07a578c72f2 3821 xorg-server_1.10.1-1ubuntu1.3.dsc
 27376c2177a012a1489b06412fd713c3412b1e2d 459987 xorg-server_1.10.1-1ubuntu1.3.diff.gz
Checksums-Sha256: 
 fb48b9ec04fcf2d523bff19d021ac89a7df8504182b24de881300a6b49da53e5 3821 xorg-server_1.10.1-1ubuntu1.3.dsc
 aedb05c01fb70d250fe81e4067c7518d11a6f4aad6b158a805be2fdb927638c5 459987 xorg-server_1.10.1-1ubuntu1.3.diff.gz
Files: 
 ee0f079cc19e846f515d3f238d9972f8 3821 x11 optional xorg-server_1.10.1-1ubuntu1.3.dsc
 1ffa6cfbcf41b7c589137867fe4e46fb 459987 x11 optional xorg-server_1.10.1-1ubuntu1.3.diff.gz
Original-Maintainer: Debian X Strike Force <debian-x at lists.debian.org>


More information about the Natty-changes mailing list