-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 03 Oct 2023 10:52:32 +0200 Source: libx11 Binary: libx11-6 libx11-6-dbgsym libx11-6-udeb libx11-dev libx11-xcb-dev libx11-xcb1 libx11-xcb1-dbgsym Architecture: armhf Version: 2:1.8.4-2+deb12u2 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Julien Cristau Description: libx11-6 - X11 client-side library libx11-6-udeb - X11 client-side library (udeb) libx11-dev - X11 client-side library (development headers) libx11-xcb-dev - Xlib/XCB interface library (development headers) libx11-xcb1 - Xlib/XCB interface library Changes: libx11 (2:1.8.4-2+deb12u2) bookworm-security; urgency=high . * CVE-2023-43785: out-of-bounds memory access in _XkbReadKeySyms() * CVE-2023-43786: stack exhaustion from infinite recursion in PutSubImage() * CVE-2023-43787: integer overflow in XCreateImage() leading to a heap overflow * XPutImage: clip images to maximum height & width allowed by protocol * XCreatePixmap: trigger BadValue error for out-of-range dimensions Checksums-Sha1: 7ec5b2802f6e70a52685c94b95a385e691b080d2 1111364 libx11-6-dbgsym_1.8.4-2+deb12u2_armhf.deb 0daffe1189003653304e585d20d095d7368706ff 508872 libx11-6-udeb_1.8.4-2+deb12u2_armhf.udeb 57290533fa0e8214b29c4eb9eb75485335fb1e52 694996 libx11-6_1.8.4-2+deb12u2_armhf.deb f1fdfe2a863af6c756d1ef97de1bd7287b28ddd2 775488 libx11-dev_1.8.4-2+deb12u2_armhf.deb 1072ad434e4a314d47ca55044fcd12ca71f83a4a 194564 libx11-xcb-dev_1.8.4-2+deb12u2_armhf.deb 98fef327fcd30b6d72f2305423c0acb20b287f5c 16964 libx11-xcb1-dbgsym_1.8.4-2+deb12u2_armhf.deb 2d5daec3b91289d25884420acbb59773935b77a2 192304 libx11-xcb1_1.8.4-2+deb12u2_armhf.deb f7d4e558cd066428c98a6ea3f035a63798bd3343 7870 libx11_1.8.4-2+deb12u2_armhf-buildd.buildinfo Checksums-Sha256: 34b35a4dbb7256ac8cd17bdbe71d0204f4ba82cb2627e1773d6cc992bb48b91a 1111364 libx11-6-dbgsym_1.8.4-2+deb12u2_armhf.deb b2d64b266b48cd0188d8d3b9af326e5a7f9159ec78f1bb14ccd62affa79b76ce 508872 libx11-6-udeb_1.8.4-2+deb12u2_armhf.udeb db706cca558b7ad919134883bb242f7dfbed7884f27753a4536174f631ddbc52 694996 libx11-6_1.8.4-2+deb12u2_armhf.deb ab924f25aa1cc4fea0ad94c6c36f627d50b592507fd85b6fd3dae705244e64db 775488 libx11-dev_1.8.4-2+deb12u2_armhf.deb 27e5624d183af535b54f0aedc9b6961e64e9826e2f5ca21f004eb762eccbd258 194564 libx11-xcb-dev_1.8.4-2+deb12u2_armhf.deb 44c0ad598e5fffe1b465fc0f89d107e353a417b79dc28e0fa41a2ff83cb2febe 16964 libx11-xcb1-dbgsym_1.8.4-2+deb12u2_armhf.deb 8763836247600074969fadef606257c319650eba81998831cac8b3a5df4c9704 192304 libx11-xcb1_1.8.4-2+deb12u2_armhf.deb 95debd9a05b66f9d74130b480bef5a036e6eb40a10c4a232d2ba233c0d7ae436 7870 libx11_1.8.4-2+deb12u2_armhf-buildd.buildinfo Files: 8eb6555b46e99936d45dc92c5db3c387 1111364 debug optional libx11-6-dbgsym_1.8.4-2+deb12u2_armhf.deb 26bbc2f0866c5de4bd66bbf3ff1583a6 508872 debian-installer optional libx11-6-udeb_1.8.4-2+deb12u2_armhf.udeb e730757348b4feddc255601cb666e16a 694996 libs optional libx11-6_1.8.4-2+deb12u2_armhf.deb b2a77ead71215be83631594fd9b86d3f 775488 libdevel optional libx11-dev_1.8.4-2+deb12u2_armhf.deb e480fcb1b6a96de9b60663a87ae18d7d 194564 libdevel optional libx11-xcb-dev_1.8.4-2+deb12u2_armhf.deb c554803fea6701a68ea19ab8fa362b9f 16964 debug optional libx11-xcb1-dbgsym_1.8.4-2+deb12u2_armhf.deb 8f6be5146a12cb41afe8b189624cb79c 192304 libs optional libx11-xcb1_1.8.4-2+deb12u2_armhf.deb 8c1659b9f9e563131692bb4e42295bca 7870 x11 optional libx11_1.8.4-2+deb12u2_armhf-buildd.buildinfo Package-Type: udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU5Ohx66NeEdc9V4jWTHLDRjMKsQFAmUb294ACgkQWTHLDRjM KsRVag//V+O4HCNNCcO6W1uUwKlEH1L9H8wGaOltkSlWXsoM+mjqya6IWJd3h1EF HnORh8bWgMgvdGNpj14t0A88/2QDkwxiREgyP9WdVQlRXOPac7wtQ5eRpDm6aVV3 iTeOgC7YTSik6qpqzrwFWLdKz6ScGVASM1NurfYt2s8puUbkvun2fg2N2qVsu7vx Z4G9nFCEMnBmunSZX7FByKO4rZuw5xBZEMQEBUEWNfD7G+QwQzEbY09UOcYJeTJQ RZh6u6qtNyaVG2ZEBGo/nrcCG0eSogkaQG+fvECVSm6/Wz+lXlDORZPRmb90f/tc 55MSZyq1RGvyc2DwxN+9H56XY1YmHulBz+8p1K3QRRTjrILRJUS7ScjKb6If0MJS d2BKz58DrnPryvwfybkVS/DOcZoe5giqhg2Why4ZIAqI1a0NOa2GGTtyzV1B/V20 YxOJ7Yshw1URV8oPHp/CiMD/80x6G3xKQVacP/DEqiLCc6KdDJVwgzEz08e6L3GM qhmsJ63Ln0rW+GvJvfxpiJrEmxpjmWxOXPyPa63h1PHrQWyTghzw8lg03d9OC0rh iDh3naiuvktnVVHTJBx2vKJXRoBNM+bJrQTsmU9VvYju4KnFggGnWWn1dYH2OkxY LXiYPG4MyLlWz2P2Q5+Oxom5mThj45euAow19IZwmll4AQBdBBg= =U++Z -----END PGP SIGNATURE-----