-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 14 Feb 2004 13:44:41 -0500 Source: xfree86 Binary: xserver-common xlibs-dev xfs xfree86-common xfonts-pex x-window-system xlibmesa-dev xspecs xlibmesa3 xfonts-cyrillic xlibmesa3-dbg xserver-xfree86 xlibs-dbg libxaw6 libxaw7 xterm xvfb xfonts-scalable xfonts-75dpi xlib6g proxymngr libxaw6-dev xlibs-pic libdps1-dbg xlib6g-dev xfonts-base xutils libxaw7-dev xnest xlibs libxaw6-dbg xmh lbxproxy libxaw7-dbg xfonts-base-transcoded xbase-clients xprt xlibosmesa3 x-window-system-core xlibosmesa-dev twm xfwp xfonts-100dpi-transcoded xlibosmesa3-dbg xfonts-100dpi xdm libdps-dev xfonts-75dpi-transcoded libdps1 Architecture: mips Version: 4.1.0-16woody3 Distribution: stable Urgency: high Maintainer: Debian/MIPS Build Daemon Changed-By: Branden Robinson Description: lbxproxy - Low Bandwidth X (LBX) proxy server libdps-dev - Display PostScript (DPS) client library development files libdps1 - Display PostScript (DPS) client library libdps1-dbg - Display PostScript (DPS) client library (unstripped) libxaw6 - X Athena widget set library (version 6) libxaw6-dbg - X Athena widget set library (version 6) (unstripped) libxaw6-dev - X Athena widget set library development files (version 6) libxaw7 - X Athena widget set library libxaw7-dbg - X Athena widget set library (unstripped) libxaw7-dev - X Athena widget set library development files proxymngr - X proxy services manager twm - Tab window manager x-window-system-core - X Window System core components xbase-clients - miscellaneous X clients xdm - X display manager xfs - X font server xfwp - X firewall proxy server xlibmesa-dev - XFree86 version of Mesa 3D graphics library development files xlibmesa3 - XFree86 version of Mesa 3D graphics library xlibmesa3-dbg - XFree86 version of Mesa 3D graphics library (unstripped) xlibs - X Window System client libraries xlibs-dbg - X Window System client libraries (unstripped) xlibs-dev - X Window System client library development files xlibs-pic - X Window System client extension library PIC archives xmh - X interface to the MH mail system xnest - nested X server xprt - X print server xserver-common - files and utilities common to all X servers xserver-xfree86 - the XFree86 X server xterm - X terminal emulator xutils - X Window System utility programs xvfb - virtual framebuffer X server Closes: 232378 Changes: xfree86 (4.1.0-16woody3) stable-security; urgency=high . * Security update release. Resolves the following issues: + CAN-2004-0083: Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CAN-2004-0084. + CAN-2004-0084: Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CAN-2004-0083. + CAN-2004-0106: Miscellaneous additional flaws in XFree86's handling of font files. . * Fix multiple buffer overflows and insufficiently rigorous input validation in the X11R6 fontfile library. (Closes: #232378) - debian/patches/075_SECURITY_libfontfile_vulnerabilities.diff Files: 64ebc1c3fbe3aee654634b8eb7842dc4 153508 x11 optional lbxproxy_4.1.0-16woody3_mips.deb cc68036544eb5195d53fc32061f48dab 174274 libs optional libdps1_4.1.0-16woody3_mips.deb 126494b9ec971c9d34176f0e89849c50 576502 devel extra libdps1-dbg_4.1.0-16woody3_mips.deb 7035f1761808978b3409c2f2c8ae3b5a 277596 devel optional libdps-dev_4.1.0-16woody3_mips.deb 40aa2b48b509b6842cce4f094207b6e8 182920 libs optional libxaw6_4.1.0-16woody3_mips.deb 8758be846c04c38d368fc81c5c42eaf9 551384 devel extra libxaw6-dbg_4.1.0-16woody3_mips.deb a529ffdbedbf7ab684a40f80293c069e 350524 devel extra libxaw6-dev_4.1.0-16woody3_mips.deb 825a9fd20ba685d4dcfb1ce0d8e68d4c 233564 libs optional libxaw7_4.1.0-16woody3_mips.deb 73054c8ede88049bf2f3fe279c2c997e 691478 devel extra libxaw7-dbg_4.1.0-16woody3_mips.deb 630417f93a1ae657e466dfc0c35ec6ee 350406 devel optional libxaw7-dev_4.1.0-16woody3_mips.deb d7a8fd3d26866e5eb666a6a378bd6dbe 77988 x11 optional proxymngr_4.1.0-16woody3_mips.deb 644d11d36a0462197bfeb77b9f7c8b74 168430 x11 optional twm_4.1.0-16woody3_mips.deb 4157ab5f66249f2d7570b6af45a2c6c0 1653382 x11 optional xbase-clients_4.1.0-16woody3_mips.deb 3353544a65ec2c93178a578debd184c8 177472 x11 optional xdm_4.1.0-16woody3_mips.deb 5fd2723a430009797132e592c7cbad47 338452 x11 optional xfs_4.1.0-16woody3_mips.deb 8c5b6d9d678a2581d665ed052095656f 83528 x11 optional xfwp_4.1.0-16woody3_mips.deb bb9c2c494334cdff820f86000dcb0dd5 358182 libs optional xlibmesa3_4.1.0-16woody3_mips.deb 7f508fe6a34754ead8108ef51e22086d 1077956 devel extra xlibmesa3-dbg_4.1.0-16woody3_mips.deb 96a64f3bfe3fdffa1db0892e5489a925 633934 devel optional xlibmesa-dev_4.1.0-16woody3_mips.deb 3d992ec716964be20a19068ada0dcdc4 1309840 libs optional xlibs_4.1.0-16woody3_mips.deb 21be2a26fe466f35ff19427e8c325b39 3734434 devel extra xlibs-dbg_4.1.0-16woody3_mips.deb 2e4a9eaf6367d167747929a344616c07 3125648 devel optional xlibs-dev_4.1.0-16woody3_mips.deb c5aede04f5b3642289b2035a7ce13fa0 78882 devel optional xlibs-pic_4.1.0-16woody3_mips.deb e28b7ef583e20f8c5af2474918b91bf2 141186 mail extra xmh_4.1.0-16woody3_mips.deb 01a23447b2ec6794f0457fa4b7ee384b 1775696 x11 optional xnest_4.1.0-16woody3_mips.deb 97cf618edbd66615f9462651b3833115 1440980 x11 optional xprt_4.1.0-16woody3_mips.deb f5f2b985b3e81967e48d0d38be58a30a 219692 x11 optional xserver-common_4.1.0-16woody3_mips.deb ea195176ad368208272f9a156da6f9a0 3386456 x11 optional xserver-xfree86_4.1.0-16woody3_mips.deb c593ced57bdc2b6aaee076a82b802ffe 506636 x11 optional xterm_4.1.0-16woody3_mips.deb 73fdd62eacf6ffcda24194ead4402117 662650 x11 optional xutils_4.1.0-16woody3_mips.deb 37f35716d9acc76b8c162687bd697163 1911062 x11 optional xvfb_4.1.0-16woody3_mips.deb bf843c2ba033c94f5284daa81c3ac5d5 60658 x11 optional x-window-system-core_4.1.0-16woody3_mips.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQFATFVFN2Dbz/1mRasRAsKyAJ908UDSYf1vGq9IaIhUfomFNKHfYACgt/BP xlYpAmZlPALAwZBWea5Chmc= =63xf -----END PGP SIGNATURE-----