2
1
Эх сурвалжийг харах

package/xserver_xorg-server: security update to 21.1.13

Fixes the following security issues:

- CVE-2024-31080: Heap buffer overread/data leakage in ProcXIGetSelectedEvents
- CVE-2024-31081: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice
- CVE-2024-31082: Heap buffer overread/data leakage in ProcAppleDRICreatePixmap
- CVE-2024-31083: User-after-free in ProcRenderAddGlyphs

For more details, see thee security page of Xorg:
https://www.x.org/wiki/Development/Security/

Signed-off-by: Waldemar Brodkorb <wbx@openadk.org>
[Peter: add actual list of CVEs]
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Waldemar Brodkorb 11 сар өмнө
parent
commit
e33db30aab

+ 3 - 3
package/x11r7/xserver_xorg-server/xserver_xorg-server.hash

@@ -1,5 +1,5 @@
-# From https://lists.x.org/archives/xorg-announce/2024-January/003442.html
-sha256  1aa0ee1adad0b2db7f291f3823a4ab240c7f4aea710e89f5ef4aa232b6833403  xorg-server-21.1.11.tar.gz
-sha512  e41bf71955691e66084a67fc20643632087f0326d5eddc31e6edd118d05005b8ab536738c181f4c352f331ec8fc8f23ae1b45f237592fa5d7eddbffe43638b08  xorg-server-21.1.11.tar.gz
+# From https://lists.x.org/archives/xorg-announce/2024-April/003504.html
+sha256  2864b6a5359ab41c5a6132c69b5d0c9af6eb85ad26d433edb012c914029de752  xorg-server-21.1.13.tar.gz
+sha512  9bf5617d577dd3526a9578daedc1f2e3527da6913841f8fc78a2bda311ebf1560e84e31942cb8133a2a2ac99487c13b9153db6fb2d00859fc24d053f6b91fe34  xorg-server-21.1.13.tar.gz
 # Locally calculated
 sha256  4cc0447a22635c7b2f1a93fec4aa94f1970fadeb72a063de006b51cf4963a06f  COPYING

+ 1 - 1
package/x11r7/xserver_xorg-server/xserver_xorg-server.mk

@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-XSERVER_XORG_SERVER_VERSION = 21.1.11
+XSERVER_XORG_SERVER_VERSION = 21.1.13
 XSERVER_XORG_SERVER_SOURCE = xorg-server-$(XSERVER_XORG_SERVER_VERSION).tar.gz
 XSERVER_XORG_SERVER_SITE = https://xorg.freedesktop.org/archive/individual/xserver
 XSERVER_XORG_SERVER_LICENSE = MIT