-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 03 Oct 2023 10:52:32 +0200 Source: libx11 Binary: libx11-6 libx11-6-dbgsym libx11-6-udeb libx11-dev libx11-xcb-dev libx11-xcb1 libx11-xcb1-dbgsym Architecture: mips64el Version: 2:1.8.4-2+deb12u2 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Julien Cristau Description: libx11-6 - X11 client-side library libx11-6-udeb - X11 client-side library (udeb) libx11-dev - X11 client-side library (development headers) libx11-xcb-dev - Xlib/XCB interface library (development headers) libx11-xcb1 - Xlib/XCB interface library Changes: libx11 (2:1.8.4-2+deb12u2) bookworm-security; urgency=high . * CVE-2023-43785: out-of-bounds memory access in _XkbReadKeySyms() * CVE-2023-43786: stack exhaustion from infinite recursion in PutSubImage() * CVE-2023-43787: integer overflow in XCreateImage() leading to a heap overflow * XPutImage: clip images to maximum height & width allowed by protocol * XCreatePixmap: trigger BadValue error for out-of-range dimensions Checksums-Sha1: 1a69e4876c6a290992b58f0b1de0653945e11807 1152216 libx11-6-dbgsym_1.8.4-2+deb12u2_mips64el.deb 0e8bdc5c2204581f134674520c91c37cb2e03602 522104 libx11-6-udeb_1.8.4-2+deb12u2_mips64el.udeb d81866b26644530758eb4c8dece950c464e3eeb9 714092 libx11-6_1.8.4-2+deb12u2_mips64el.deb 384609fcfec711a67431e470860e4558d2a4a47b 842492 libx11-dev_1.8.4-2+deb12u2_mips64el.deb 61ac5f649db1de43e7249ee3fb83501c1c6cccfe 194672 libx11-xcb-dev_1.8.4-2+deb12u2_mips64el.deb f8e51b67bcf112bdd25ac2d6d53d37adb0545357 16872 libx11-xcb1-dbgsym_1.8.4-2+deb12u2_mips64el.deb 11689c7f79c8de0a6de968622da2367ff7e8c290 192448 libx11-xcb1_1.8.4-2+deb12u2_mips64el.deb 37c4f013c70ae33c17d255109074cb640a3ac7f5 7892 libx11_1.8.4-2+deb12u2_mips64el-buildd.buildinfo Checksums-Sha256: d48824de3d0390557adb622f7c902db3f5b76ec2764c10a15096eb1705386e0a 1152216 libx11-6-dbgsym_1.8.4-2+deb12u2_mips64el.deb 14c9fcfb3b46bee8eca570e8e3ee2cba6f3ff92c8fc746348dd5c28a41b0ca98 522104 libx11-6-udeb_1.8.4-2+deb12u2_mips64el.udeb d5e86b1630fde442f14647405c801c8aab858b26a19650d34a14b7c76ed679ec 714092 libx11-6_1.8.4-2+deb12u2_mips64el.deb 31bf4bcf411e53f206778bdb0d40bd8e85d2d675d634a2a4aa4dfdac49681490 842492 libx11-dev_1.8.4-2+deb12u2_mips64el.deb e0f0d31909108ea109b5df2aa79234ae3a75b9133d83fe8017d26709d5190520 194672 libx11-xcb-dev_1.8.4-2+deb12u2_mips64el.deb 70920df5d8a8eef6b3a85dbdc64e44abdcd43f07bf2c723cb8c78160db4d0a91 16872 libx11-xcb1-dbgsym_1.8.4-2+deb12u2_mips64el.deb 88941a3fd15895dd6950bc4530fdbd8ee386fddaed95cff1a4e3af7cab3293aa 192448 libx11-xcb1_1.8.4-2+deb12u2_mips64el.deb ece1fdfe18e6b2dd77628debbddd9edb253718eaf1e64e69e50098d5d4089f7e 7892 libx11_1.8.4-2+deb12u2_mips64el-buildd.buildinfo Files: 97539a523da8d4faed4bbd58b62c9c08 1152216 debug optional libx11-6-dbgsym_1.8.4-2+deb12u2_mips64el.deb 0ea32b4093290e80a44e093f6f56b2b1 522104 debian-installer optional libx11-6-udeb_1.8.4-2+deb12u2_mips64el.udeb 267ffed555db0e544e3a9482f8f3af6b 714092 libs optional libx11-6_1.8.4-2+deb12u2_mips64el.deb 851926a8f177b1ed95432a159e9cc45b 842492 libdevel optional libx11-dev_1.8.4-2+deb12u2_mips64el.deb 58c12a3b7d2ad95e53582890783914a3 194672 libdevel optional libx11-xcb-dev_1.8.4-2+deb12u2_mips64el.deb 5d70ce1ee6c96b76ea2070fdb8aacf81 16872 debug optional libx11-xcb1-dbgsym_1.8.4-2+deb12u2_mips64el.deb d9a0a3eab8f6b4e86b422c320848c98e 192448 libs optional libx11-xcb1_1.8.4-2+deb12u2_mips64el.deb 39d8d104df9334a597208911f25d82ab 7892 x11 optional libx11_1.8.4-2+deb12u2_mips64el-buildd.buildinfo Package-Type: udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEbqxhtqqT8knLtgp0Ct/wWqReXfQFAmUb27QACgkQCt/wWqRe XfQVxg/7BZrLqsk9Xfs+iujtOBcFtsES5zQeY/WIaf1uUyzmFuQ6hs6Rls0ApQOm rkaEcZ41hZt3c5rrDpGGTdujT8FJkamShShmHZ1IB5JsCCJB/nAPb6hy1+tBiRiF zvhKNPRZPNo6fJgwO5Cb8ndHQ/hw/Gk95kA6fVSQsfleeYZ3zW+n+ys2yUSNYr7+ 7NnnxuLTS0+e4l28SEzd44Wn7F4jXgvrEIvmAGF3JARi+MFHqdzr9vphq6r0+WtO hyABQIFpcVVmfZvQ58O3DRUub4Iw5PfHEN3cSSVvMRFNPrpjW12mtP1RhjVoHhr4 hABlBcDzRFVn89vCtedUcyxs0Z3Rh9rReokhlOQaZDvF7Vqvz0Wg6sTAUViwFNGX McKe4Odp+MhgnBKKUuxSuiaoJMOzoQIy/BMux5NRQqSRL4IH01k7Z+hMIPxTYwgK wdx7yIdoMrgfDurfqtos905IyPvsd9jBOKLPaixkGFwYxEGr05aolguWmYX88JYD JJokv4OQMcdZCoJF/txwjvNvxlOZX1PhrZemC20fzMIpUKVZ44ud1Jaicv0oyEVK wG+OpDa9at9XuP33qMbDy7Tc5bBKXjx1mz7grmNEQ7TCSMgzMHcMPnvN2UF7XVIu IR9VABNO1KoP5EXl9YPSIDGKhFYAhPggkZ4wy8lPrlCwgo1iyQk= =/l4K -----END PGP SIGNATURE-----