-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 14 Feb 2004 13:44:41 -0500 Source: xfree86 Binary: xserver-common xlibs-dev xfs xfree86-common xfonts-pex x-window-system xlibmesa-dev xspecs xlibmesa3 xfonts-cyrillic xlibmesa3-dbg xserver-xfree86 xlibs-dbg libxaw6 libxaw7 xterm xvfb xfonts-scalable xfonts-75dpi xlib6g proxymngr libxaw6-dev xlibs-pic libdps1-dbg xlib6g-dev xfonts-base xutils libxaw7-dev xnest xlibs libxaw6-dbg xmh lbxproxy libxaw7-dbg xfonts-base-transcoded xbase-clients xprt xlibosmesa3 x-window-system-core xlibosmesa-dev twm xfwp xfonts-100dpi-transcoded xlibosmesa3-dbg xfonts-100dpi xdm libdps-dev xfonts-75dpi-transcoded libdps1 Architecture: ia64 Version: 4.1.0-16woody3 Distribution: stable-security Urgency: high Maintainer: Debian/IA64 Build Daemon Changed-By: Branden Robinson Description: lbxproxy - Low Bandwidth X (LBX) proxy server libdps-dev - Display PostScript (DPS) client library development files libdps1 - Display PostScript (DPS) client library libdps1-dbg - Display PostScript (DPS) client library (unstripped) libxaw6 - X Athena widget set library (version 6) libxaw6-dbg - X Athena widget set library (version 6) (unstripped) libxaw6-dev - X Athena widget set library development files (version 6) libxaw7 - X Athena widget set library libxaw7-dbg - X Athena widget set library (unstripped) libxaw7-dev - X Athena widget set library development files proxymngr - X proxy services manager twm - Tab window manager x-window-system-core - X Window System core components xbase-clients - miscellaneous X clients xdm - X display manager xfs - X font server xfwp - X firewall proxy server xlibmesa-dev - XFree86 version of Mesa 3D graphics library development files xlibmesa3 - XFree86 version of Mesa 3D graphics library xlibmesa3-dbg - XFree86 version of Mesa 3D graphics library (unstripped) xlibosmesa-dev - Mesa/XFree86 off-screen rendering library development files xlibosmesa3 - Mesa/XFree86 off-screen rendering library xlibosmesa3-dbg - Mesa/XFree86 off-screen rendering library (unstripped) xlibs - X Window System client libraries xlibs-dbg - X Window System client libraries (unstripped) xlibs-dev - X Window System client library development files xlibs-pic - X Window System client extension library PIC archives xmh - X interface to the MH mail system xnest - nested X server xprt - X print server xserver-common - files and utilities common to all X servers xserver-xfree86 - the XFree86 X server xterm - X terminal emulator xutils - X Window System utility programs xvfb - virtual framebuffer X server Closes: 232378 Changes: xfree86 (4.1.0-16woody3) stable-security; urgency=high . * Security update release. Resolves the following issues: + CAN-2004-0083: Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CAN-2004-0084. + CAN-2004-0084: Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CAN-2004-0083. + CAN-2004-0106: Miscellaneous additional flaws in XFree86's handling of font files. . * Fix multiple buffer overflows and insufficiently rigorous input validation in the X11R6 fontfile library. (Closes: #232378) - debian/patches/075_SECURITY_libfontfile_vulnerabilities.diff Files: b0e26a6d972ca56739a008f708e79cbd 191862 x11 optional lbxproxy_4.1.0-16woody3_ia64.deb f36f7e60b33659059f51d61a3d9359dc 241664 libs optional libdps1_4.1.0-16woody3_ia64.deb 5559772145b05a8abf8f74d84278a564 825300 devel extra libdps1-dbg_4.1.0-16woody3_ia64.deb 8efa6a6dd0ab78e9c804e78e9ce3096d 322322 devel optional libdps-dev_4.1.0-16woody3_ia64.deb 9e540630e31d9a9d8d28e4089100d53a 258302 libs optional libxaw6_4.1.0-16woody3_ia64.deb 8a6c8282d0a512857ec0695db1c4ea50 1167700 devel extra libxaw6-dbg_4.1.0-16woody3_ia64.deb 2a73f1e303d2341b6eccfbca8a93f48d 444444 devel extra libxaw6-dev_4.1.0-16woody3_ia64.deb ee7b150a5332cd6cb5da90b33c338a04 340530 libs optional libxaw7_4.1.0-16woody3_ia64.deb e6293df4266a98fa01f58c5e97bde225 1334132 devel extra libxaw7-dbg_4.1.0-16woody3_ia64.deb 5473ffa5fc3a7ad38b0b63437ebb6d2d 444324 devel optional libxaw7-dev_4.1.0-16woody3_ia64.deb c1147bd3716b240a33edaca241737fc8 84112 x11 optional proxymngr_4.1.0-16woody3_ia64.deb 76be86fb1ee7154cfa3c56c03a1f5639 207962 x11 optional twm_4.1.0-16woody3_ia64.deb 923d6a075445dd08ebe5188208ed68b9 2410264 x11 optional xbase-clients_4.1.0-16woody3_ia64.deb 0affffd8a3bb7234ed59c43932852abc 211194 x11 optional xdm_4.1.0-16woody3_ia64.deb ae66008eaffba47612e1126fdb5e9b99 474174 x11 optional xfs_4.1.0-16woody3_ia64.deb cf1453b5b8e1932efac89d050a05e5b8 91326 x11 optional xfwp_4.1.0-16woody3_ia64.deb 393bcb65f1e53c15f674f1385f1ae7e0 5185762 libs optional xlibmesa3_4.1.0-16woody3_ia64.deb 93463be02304d99d802b0bc308db5157 2394946 devel extra xlibmesa3-dbg_4.1.0-16woody3_ia64.deb 376642583e7fafdbd3f339951c9f3624 743766 devel optional xlibmesa-dev_4.1.0-16woody3_ia64.deb 13c38a409f1a12fbde78ba03f1a3bf52 756148 libs optional xlibosmesa3_4.1.0-16woody3_ia64.deb 93cd4ee45810a6874d3508a4b36db535 3199636 devel extra xlibosmesa3-dbg_4.1.0-16woody3_ia64.deb 2419baa6e6f82a617ae7b0490fa1beb2 832054 devel optional xlibosmesa-dev_4.1.0-16woody3_ia64.deb 3a670766774cf444763ecb7fdffb599d 1652690 libs optional xlibs_4.1.0-16woody3_ia64.deb f3dff607d9b04ebae9cadf03ab40887b 18060914 devel extra xlibs-dbg_4.1.0-16woody3_ia64.deb fab56ad95c0a28a91ba2ad267fad8af9 3513724 devel optional xlibs-dev_4.1.0-16woody3_ia64.deb f002ef04ec381975c11cb9e692c4e979 89486 devel optional xlibs-pic_4.1.0-16woody3_ia64.deb b56e6894528921a66a7303f28e64c58a 170518 mail extra xmh_4.1.0-16woody3_ia64.deb 58f690f738581599355399d0a84e22ed 2370960 x11 optional xnest_4.1.0-16woody3_ia64.deb 40941779d953b55094b5c899fa5b2948 1895620 x11 optional xprt_4.1.0-16woody3_ia64.deb 3ea69688bbba1e1bee66340ab48b4345 221768 x11 optional xserver-common_4.1.0-16woody3_ia64.deb 46f61248a972df174e1a5e835b4dcd16 6901592 x11 optional xserver-xfree86_4.1.0-16woody3_ia64.deb af122eca12678aa2a1ea7294381780db 566986 x11 optional xterm_4.1.0-16woody3_ia64.deb 31229d60d97c0640500dc81f3465a577 816118 x11 optional xutils_4.1.0-16woody3_ia64.deb 98d9f74691354843c779a52c7dbe151e 2572114 x11 optional xvfb_4.1.0-16woody3_ia64.deb 19a6f96aa8449ba1087a907174ab46d1 60654 x11 optional x-window-system-core_4.1.0-16woody3_ia64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFAND5HArxCt0PiXR4RArrcAJ9ux6k0sO/k1SBejvzFvs6p+mxttwCfanwr j3vbZMWxuLOIPapMINFaWPA= =XYgY -----END PGP SIGNATURE-----