-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3905-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff July 09, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xorg-server CVE ID : CVE-2017-10971 CVE-2017-10972 Debian Bug : 867492 Two security issues have been discovered in the X.org X server, which may lead to privilege escalation or an information leak. For the oldstable distribution (jessie), these problems have been fixed in version 2:1.16.4-1+deb8u1. For the stable distribution (stretch), these problems have been fixed in version 2:1.19.2-1+deb9u1. Setups running root-less X are not affected. For the testing distribution (buster), these problems have been fixed in version 2:1.19.3-2. For the unstable distribution (sid), these problems have been fixed in version 2:1.19.3-2. We recommend that you upgrade your xorg-server packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAllilJAACgkQEMKTtsN8 TjYfGxAAj4PL+dnOX0CNbm+NJ/hW5nw0xwCrDiN8QzCJf/CDaPym+MhdB4wSEeJw pTCDxqTrt2cqAtOAIRexpq8Hx64L0nW2kuBriaQHpRronULyrVZiCheeIlyIEP4P lHeH2WtzPuY++yRq3NauM/ylnDzjFBaMCaIO4yUNetJ8+j8bpaGeW7/KOhTqTfab e+WQLcRaWO+Ple3A5YXHZWRvebeaPtL539oucdx7IBOIuXIGqH6FZ9RcH0c8GTQN qjaPNDeeU5VK93i0D93yoBVT9VpDI3B9SoPghsCmRsDDUZ9I9/xelzoKDdtClRmW 9X9QyOSpD8Qp5umad78Bqin02A5F4lLOYtPHCv0dokICP7tmRE/6Rxu3qvjnt4n7 689yeidSUqZ9Z350bDz/rafRCcz5u/hon3QnUChl6MBFTkSYpPMOfMwpGz4DN5Hg egqmV6qDRtCp1nSnOHThBzKQnRIn5JZdyiZ0na5bVsMYvp26IP+2yZO/2P8d+zOn Crd/TLxI9C04+1mfEH14rT84FUvO76FBUfyd1q4Urb7/laMJ/HtkC3MPQ4Diaqmo lQ4w+yeKf3/XoKZii6fz/sMNc73XDV6fleT1/9FsjbXaa1CD5ZOvYRcVPs3sYpAu ZKp5L1vlSuzLDd2jCDYvRRKRBQFvQ3aXiL8zbdrdzQipx5pPufk= =a7RZ -----END PGP SIGNATURE-----