libx11 (2:1.4.99.1-0ubuntu2.5) precise-security; urgency=medium
[ Marc Deslauriers ]
* SECURITY UPDATE: integer overflow and heap overflow in XIM client
- debian/patches/CVE-2020-14344-1.patch: fix signed length values in
modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-2.patch: fix integer overflows in
modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-3.patch: fix more unchecked lengths in
modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-4.patch: zero out buffers in functions
in modules/im/ximcp/imDefIc.c, modules/im/ximcp/imDefIm.c.
- debian/patches/CVE-2020-14344-5.patch: change the data_len parameter
to CARD16 in modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-6.patch: fix size calculation in
modules/im/ximcp/imRmAttr.c.
- debian/patches/CVE-2020-14344-7.patch: fix input clients connecting
to server in modules/im/ximcp/imRmAttr.c.
- CVE-2020-14344
* SECURITY UPDATE: integer overflow and double free in locale handling
- debian/patches/CVE-2020-14363.patch: fix an integer overflow in
modules/om/generic/omGeneric.c.
- CVE-2020-14363
libx11 (2:1.4.99.1-0ubuntu2.4) precise-security; urgency=medium
* SECURITY UPDATE: Out-of-bounds read
- debian/patches/CVE-2016-7942.patch: fix in src/GetImage.c.
- CVE-2016-7942
* SECURITY UPDATE: Out-of-bounds read
- debian/patches/CVE-2016-7943.patch: fix in src/FontNames.c,
src/ListExt.c, src/ModMap.c.
- CVE-2016-7943
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2018-14598.patch: fix in src/GetFPath.c,
src/ListExt.c.
- CVE-2018-14598
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2018-14599.patch: fix in src/FontNames.c,
src/GetFPath.c, src/ListExt.c.
- CVE-2018-14599
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2018-14600.patch: fix in src/GetFPath.
- CVE-2018-14600
Date: 2020-09-02 17:55:14.309433+00:00
Changed-By: leo.barb...@canonical.com (Leonidas S. Barbosa)
Signed-By: Steve Langasek <steve.langa...@canonical.com>
https://launchpad.net/ubuntu/+source/libx11/2:1.4.99.1-0ubuntu2.5
Sorry, changesfile not available.
--
Precise-changes mailing list
Precise-changes@lists.ubuntu.com
Modify settings or unsubscribe at:
https://lists.ubuntu.com/mailman/listinfo/precise-changes