-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 03 Oct 2023 10:52:32 +0200 Source: libx11 Binary: libx11-6 libx11-6-dbgsym libx11-6-udeb libx11-dev libx11-xcb-dev libx11-xcb1 libx11-xcb1-dbgsym Architecture: mipsel Version: 2:1.8.4-2+deb12u2 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Julien Cristau Description: libx11-6 - X11 client-side library libx11-6-udeb - X11 client-side library (udeb) libx11-dev - X11 client-side library (development headers) libx11-xcb-dev - Xlib/XCB interface library (development headers) libx11-xcb1 - Xlib/XCB interface library Changes: libx11 (2:1.8.4-2+deb12u2) bookworm-security; urgency=high . * CVE-2023-43785: out-of-bounds memory access in _XkbReadKeySyms() * CVE-2023-43786: stack exhaustion from infinite recursion in PutSubImage() * CVE-2023-43787: integer overflow in XCreateImage() leading to a heap overflow * XPutImage: clip images to maximum height & width allowed by protocol * XCreatePixmap: trigger BadValue error for out-of-range dimensions Checksums-Sha1: d57c8fb8420cbee1fc48e512233a5934f070c716 1134928 libx11-6-dbgsym_1.8.4-2+deb12u2_mipsel.deb 118a8746fcf1e4ff143375f9d9af587b910aeb8b 521496 libx11-6-udeb_1.8.4-2+deb12u2_mipsel.udeb b0e028c456537305ecd4e3f9db272846c753b068 711740 libx11-6_1.8.4-2+deb12u2_mipsel.deb 8589949fd91897fe7ff2d553e7051cd455e5c289 831420 libx11-dev_1.8.4-2+deb12u2_mipsel.deb 064d0adb94939d7c4845960100356d3b79506ef8 194644 libx11-xcb-dev_1.8.4-2+deb12u2_mipsel.deb 7263934937984deaef6d6f1e76bef8203921992e 16860 libx11-xcb1-dbgsym_1.8.4-2+deb12u2_mipsel.deb c520306d54aea425025a18e7a2c0456f1297ba4f 192344 libx11-xcb1_1.8.4-2+deb12u2_mipsel.deb 9c0ac4cda5cad4007ced914c21d719721237380f 7839 libx11_1.8.4-2+deb12u2_mipsel-buildd.buildinfo Checksums-Sha256: c3d3c603e952d2bb19018597bdac793a39150cb65af154549d844c3dfe90cabb 1134928 libx11-6-dbgsym_1.8.4-2+deb12u2_mipsel.deb 927ff149a321431e3350f5a7725b5408e7ff920e5c402f175149364575d8a465 521496 libx11-6-udeb_1.8.4-2+deb12u2_mipsel.udeb c968bde7768ef4dffe56bd977cd6b19b229b9261c06e4088117646410a16994c 711740 libx11-6_1.8.4-2+deb12u2_mipsel.deb ea0bb83b4f210ade2795873fb4453dea62a71eef99ae6b0128b461b536b9f787 831420 libx11-dev_1.8.4-2+deb12u2_mipsel.deb 7ecf5538794b98e70d5eec1fc6cfa09ee7f55acd10fed6ab3ce2e12d5d18b838 194644 libx11-xcb-dev_1.8.4-2+deb12u2_mipsel.deb b38d17015430151cb285e790d39d870ea96336ef5793d9130633ec23079305bd 16860 libx11-xcb1-dbgsym_1.8.4-2+deb12u2_mipsel.deb 3a05e72003d5821304d87129e55c64ec5af6d3456b6cc0b8779fc9a2be175eef 192344 libx11-xcb1_1.8.4-2+deb12u2_mipsel.deb 3bb38df8c7f26e969d453d85085bb8b97fcb3798db8df3286690b213f0145c3e 7839 libx11_1.8.4-2+deb12u2_mipsel-buildd.buildinfo Files: 386218fe4e519b935988a6bf1fe04691 1134928 debug optional libx11-6-dbgsym_1.8.4-2+deb12u2_mipsel.deb 2ee385979351d5fe1c1856ce01f118a3 521496 debian-installer optional libx11-6-udeb_1.8.4-2+deb12u2_mipsel.udeb e24d8a5cb34e8becd8fe2df243d6e2bf 711740 libs optional libx11-6_1.8.4-2+deb12u2_mipsel.deb a70f9a7a4396102acc9e8c9eb786a82f 831420 libdevel optional libx11-dev_1.8.4-2+deb12u2_mipsel.deb afd949261d0f75d26880380917d597eb 194644 libdevel optional libx11-xcb-dev_1.8.4-2+deb12u2_mipsel.deb c5437f49a34d54f274a1baabb81856cb 16860 debug optional libx11-xcb1-dbgsym_1.8.4-2+deb12u2_mipsel.deb 7330dac4de750a60717cc104abd7532f 192344 libs optional libx11-xcb1_1.8.4-2+deb12u2_mipsel.deb 1e08947b071481dc0324d4638f62479c 7839 x11 optional libx11_1.8.4-2+deb12u2_mipsel-buildd.buildinfo Package-Type: udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXUZVEjohYGA7PDpMojl408mCs9YFAmUb2/MACgkQojl408mC s9Y0sQ/9GvmYzRHnt56xyObOc+CGmN4QNArqyNQ57A+LAZOE6KWEXENPQdgjxA6a H4u+v2v12sEQmLjSHHdof4+zoE+cOZ//s/wK0tVn6tck4wmViupLSqhj5jQCl92q Mrvyw+V8G58KjMSajN//4qW16kgQ5dzVb6UJzzvGDJGWSm5xnP0h72PUS62FKpoK 45Ogmo/gu/HjZZIxjzle8L0joEZUDaPJ9ZysUImEND/oJpB03BDOKosq0LwAOplQ /Cnab7YyYTnz2yYczKtjwJfNgyOdY7UHILSeLSMifLgMt7gd2Fj1NilDrnFrIVqV 0i85quH8qnKJ6FdMViTGHeIbUwlk5w/AQCEq1Z8Vepx76tbT4MPgiBFZPmPsRNYz 0kLS84HO+sU3Nv/6GalZZIWZtZh3+WsVl8Hi+h2P4IOBdcF68czENQbiHJ3/jPaZ bidNT7EutPDLRrl8Exh+7x+4CD7Q5eY4OMJyFuC+fkNWspVCHLvxII/ldFIxaBdF hX+lrq4DxfBg+DzZwtA16W5ppYSPfjWMv/6h2ldC827vw36e0HFBme6xUSGpPjI7 5dXsRZb2NRdgBkf5StIHs8Phf2Zst3/+2CeL2uca3iMYvTsKQIfJodoShn1m8kIs GqARuhFrff8JQfPv/ZuGb12b2wPocvncdi0DKzuiYl9gWxRgiwM= =Ma96 -----END PGP SIGNATURE-----