ubuntu/+source/xorg-server:ubuntu/xenial-security

Last commit made on 2017-10-17
Get this branch:
git clone -b ubuntu/xenial-security https://git.launchpad.net/ubuntu/+source/xorg-server
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
ubuntu/xenial-security
Repository:
lp:ubuntu/+source/xorg-server

Recent commits

037efda... by Marc Deslauriers on 2017-10-13

Import patches-unapplied version 2:1.18.4-0ubuntu0.7 to ubuntu/xenial-security

Imported using git-ubuntu import.

Changelog parent: ec1ea12c0abd4b50a92e52f71878a7123d08fab9

New changelog entries:
  * SECURITY UPDATE: unvalidated extra length in ProcEstablishConnection
    - debian/patches/CVE-2017-12176.patch: add check to dix/dispatch.c.
    - CVE-2017-12176
  * SECURITY UPDATE: Unvalidated variable-length request in
    ProcDbeGetVisualInfo
    - debian/patches/CVE-2017-12177.patch: add check to dbe/dbe.c.
    - CVE-2017-12177
  * SECURITY UPDATE: wrong extra length check in ProcXIChangeHierarchy
    - debian/patches/CVE-2017-12178.patch: fix length check in
      Xi/xichangehierarchy.c.
    - CVE-2017-12178
  * SECURITY UPDATE: integer overflow and unvalidated length in
    ProcXIBarrierReleasePointer
    - debian/patches/CVE-2017-12179-1.patch: test exact size of
      XIBarrierReleasePointer in Xi/xibarriers.c.
    - debian/patches/CVE-2017-12179-2.patch: add checks to Xi/xibarriers.c.
    - CVE-2017-12179
  * SECURITY UPDATE: various unvalidated lengths
    - debian/patches/CVE-2017-12180-12182.patch: add more checks to
      Xext/vidmode.c, hw/xfree86/common/xf86DGA.c,
      hw/xfree86/dri/xf86dri.c.
    - CVE-2017-12180
    - CVE-2017-12181
    - CVE-2017-12182
  * SECURITY UPDATE: more unvalidated lengths
    - debian/patches/CVE-2017-12183.patch: add checks to xfixes/cursor.c,
      xfixes/region.c, xfixes/saveset.c, xfixes/xfixes.c.
    - CVE-2017-12183
  * SECURITY UPDATE: even more unvalidated lengths
    - debian/patches/CVE-2017-12184-12187.patch: add more checks to
      Xext/panoramiX.c, Xext/saver.c, Xext/xres.c, Xext/xvdisp.c,
      hw/dmx/dmxpict.c, pseudoramiX/pseudoramiX.c, render/render.c.
    - CVE-2017-12184
    - CVE-2017-12185
    - CVE-2017-12186
    - CVE-2017-12187
  * debian/patches/os_big_requests.patch: make sure big requests have
    sufficient length in os/io.c.
  * debian/patches/xkb_escape_fix.patch: escape non-printable characters
    correctly in xkb/xkbtext.c.

ec1ea12... by Marc Deslauriers on 2017-10-11

Import patches-unapplied version 2:1.18.4-0ubuntu0.6 to ubuntu/xenial-security

Imported using git-ubuntu import.

Changelog parent: 381cfe998a42132c26d2ed0b72f8fee9ca2895c5

New changelog entries:
  * SECURITY UPDATE: DoS or segment overwrite via shmseg resource id
    - debian/patches/CVE-2017-13721.patch: validate shmseg resource id in
      Xext/shm.c.
    - CVE-2017-13721
  * SECURITY UPDATE: buffer overflow via XKB data
    - debian/patches/CVE-2017-13723.patch: handle xkb formatted string
      output safely in xkb/xkbtext.c.
    - CVE-2017-13723
  * This update does _not_ contain the changes from 2:1.18.4-0ubuntu0.5 in
    xenial-proposed.

381cfe9... by Timo Aaltonen on 2017-06-26

Import patches-unapplied version 2:1.18.4-0ubuntu0.4 to ubuntu/xenial-proposed

Imported using git-ubuntu import.

Changelog parent: 46640fd007a46f866f36fd8ea28e1540c678b313

New changelog entries:
  * control: Build against libxfont1-dev. (LP: #1687981, #1707691)
  * disable-rotation-transform-gpuscreens.patch: Dropped, NVIDIA driver
    supports rotation now. (LP: #1706287)

46640fd... by Marc Deslauriers on 2017-07-17

Import patches-unapplied version 2:1.18.4-0ubuntu0.3 to ubuntu/xenial-security

Imported using git-ubuntu import.

Changelog parent: 439f7a61874f583b58cff76e333125032900cfe4

New changelog entries:
  * SECURITY UPDATE: DoS and possible code execution in endianness
    conversion of X Events
    - debian/patches/CVE-2017-10971-1.patch: do not try to swap
      GenericEvent in Xi/sendexev.c.
    - debian/patches/CVE-2017-10971-2.patch: verify all events in
      ProcXSendExtensionEvent in Xi/sendexev.c.
    - debian/patches/CVE-2017-10971-3.patch: disallow GenericEvent in
      SendEvent request in dix/events.c, dix/swapreq.c.
    - CVE-2017-10971
  * SECURITY UPDATE: information leak in XEvent handling
    - debian/patches/CVE-2017-10972.patch: zero target buffer in
      SProcXSendExtensionEvent in Xi/sendexev.c.
    - CVE-2017-10972
  * SECURITY UPDATE: MIT-MAGIC-COOKIES timing attack
    - debian/patches/CVE-2017-2624.patch: use timingsafe_memcmp() in
      configure.ac, include/dix-config.h.in, include/os.h,
      os/mitauth.c, os/timingsafe_memcmp.c.
    - CVE-2017-2624

439f7a6... by Timo Aaltonen on 2016-11-01

Import patches-unapplied version 2:1.18.4-0ubuntu0.2 to ubuntu/xenial-proposed

Imported using git-ubuntu import.

Changelog parent: 0d1f3be822f00c734cf8fe46f74e4eec33be192d

New changelog entries:
  * modesetting-unifdef-slave-support.diff: Fix modesetting slave output
    names. (LP: #1636397)

0d1f3be... by Timo Aaltonen on 2016-09-01

Import patches-unapplied version 2:1.18.4-0ubuntu0.1 to ubuntu/xenial-proposed

Imported using git-ubuntu import.

Changelog parent: 534d521870bc2fd56e427f303c21d3eec967636d

New changelog entries:
  * New upstream bugfix release. (LP: #1619142)
  * randr-adjust-masters-last-set-time.diff,
    randr-do-not-check-the-screen-size.diff:
    Fix issues changing display mode on prime setups. (LP: #1586260)
  * os-treat-ssh-as-a-non-local-client.diff: Dropped, upstream.
  * drm_device_keep_trying.patch: Dropped, shouldn't be needed anymore,
    and causes issues on non-x86 archs. (LP: #1581076)
  * debian/patches/xmir.patch: backport XMir fixes from Ubuntu "Yakkety Yak"
    - fix button/menu focus failures (lp: #1590553)
    - ignore 'unnkown 11 event' (lp: #1617925)
    - don't call epoxy every frame (lp: #1617932)
    - fix unclickable parts of the screen after rotation (lp: #1613708)
    - fix key repeat issues (lp: #1591356)

534d521... by Timo Aaltonen on 2016-07-21

Import patches-unapplied version 2:1.18.3-1ubuntu2.3 to ubuntu/xenial-proposed

Imported using git-ubuntu import.

Changelog parent: 06462f234e44fa01da2c082c53dfc096fe6cca97

New changelog entries:
  [ Timo Aaltonen ]
  * control: Add Conflicts/Replaces on xserver-xorg-video-glamoregl.
    (LP: #1574320)
  [ Ɓukasz 'sil2100' Zemczak ]
  * debian/control, debian/rules:
    - Build xmir for arm64 (LP: #1604851).

06462f2... by Robert Ancell on 2016-05-04

Import patches-unapplied version 2:1.18.3-1ubuntu2.2 to ubuntu/xenial-proposed

Imported using git-ubuntu import.

Changelog parent: 94098c3d1f45dcc62577a2fe7e040f083488b97d

New changelog entries:
  * debian/patches/xmir.patch:
    - Fix recently added keymap code
  * debian/patches/xmir-fixes.diff:
    - Merged into xmir.patch

94098c3... by Robert Ancell on 2016-04-29

Import patches-unapplied version 2:1.18.3-1ubuntu2.1 to ubuntu/xenial-proposed

Imported using git-ubuntu import.

Changelog parent: 23c735b0f8833ecb8a84a98b11278ba8e1c0c798

New changelog entries:
  * debian/patches/xmir.patch:
    - Pass keymap from Mir to Xkb (LP: #1566487)

23c735b... by Timo Aaltonen on 2016-04-07

Import patches-unapplied version 2:1.18.3-1ubuntu2 to ubuntu/xenial-proposed

Imported using git-ubuntu import.

Changelog parent: 8544022c8a3871ef8b4e277ad0934cbbd70206d0

New changelog entries:
  * Disable 190_cache-xkbcomp_output_for_fast_start_up.patch for now,
    compiling the keymap fails in current xenial for some reason.
    (LP: #1566878)