Bug#976216: xorg-server: CVE-2020-25712 CVE-2020-14360

2020-12-02 Thread Julien Cristau
On Wed, Dec 02, 2020 at 12:10:43PM +0100, Moritz Muehlenhoff wrote: > I'll compare them with yours tonight, but I'd expect them to be identical > given > how close buster is to upstream. > Yeah, they're the same. Thanks for getting this rolling. Cheers, Julien

Bug#976216: xorg-server: CVE-2020-25712 CVE-2020-14360

2020-12-02 Thread Moritz Muehlenhoff
On Wed, Dec 02, 2020 at 11:49:24AM +0100, Julien Cristau wrote: > Hi, > > On Tue, Dec 01, 2020 at 05:58:56PM +0100, Salvatore Bonaccorso wrote: > > The following vulnerabilities were published for xorg-server. > > > > CVE-2020-25712[0]: > > | Fix XkbSetDeviceInfo() and SetDeviceIndicators() heap

Bug#976216: xorg-server: CVE-2020-25712 CVE-2020-14360

2020-12-02 Thread Julien Cristau
Hi, On Tue, Dec 01, 2020 at 05:58:56PM +0100, Salvatore Bonaccorso wrote: > The following vulnerabilities were published for xorg-server. > > CVE-2020-25712[0]: > | Fix XkbSetDeviceInfo() and SetDeviceIndicators() heap overflows > > CVE-2020-14360[1]: > | Check SetMap request length carefully >

Bug#976216: xorg-server: CVE-2020-25712 CVE-2020-14360

2020-12-01 Thread Salvatore Bonaccorso
Source: xorg-server Version: 2:1.20.4-1+deb10u1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1 2:1.20.4-1 Control: found -1 2:1.20.8-2 Control: found -1 2:1.20.9-2 Hi, The following vulnerabilities were published for xorg-server.