-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 16 Dec 2011 19:54:40 +0100 Source: xorg Binary: x11-common xserver-xorg xserver-xorg-video-all xserver-xorg-input-all xorg xorg-dev xlibmesa-gl xlibmesa-gl-dev xlibmesa-glu libglu1-xorg libglu1-xorg-dev xbase-clients xutils Architecture: i386 Version: 1:7.5+8+squeeze1 Distribution: squeeze-security Urgency: low Maintainer: i386 Build Daemon Changed-By: Julien Cristau Description: libglu1-xorg - transitional package for Debian etch libglu1-xorg-dev - transitional package for Debian etch x11-common - X Window System (X.Org) infrastructure xbase-clients - miscellaneous X clients - metapackage xlibmesa-gl - transitional package for Debian etch xlibmesa-gl-dev - transitional package for Debian etch xlibmesa-glu - transitional package for Debian etch xorg - X.Org X Window System xorg-dev - the X.Org X Window System development libraries xserver-xorg - the X.Org X server xserver-xorg-input-all - the X.Org X server -- input driver metapackage xserver-xorg-video-all - the X.Org X server -- output driver metapackage xutils - X Window System utility programs metapackage Closes: 652249 Changes: xorg (1:7.5+8+squeeze1) squeeze-security; urgency=low . * xserver-wrapper: when we drop privileges, don't forget to also reset effective group id, since we're installed setgid root. * xserver-wrapper: revert change to allow devices with major 5 as consoles. This includes things like /dev/tty and /dev/ptmx, which are world-readable (closes: #652249). Thanks to vladz for the report. Reference: CVE-2011-4613. Checksums-Sha1: f64da4dfcf38e0da0c02458eb0ce1c8ba18ba153 53334 xserver-xorg_7.5+8+squeeze1_i386.deb e6a395768d8413f377cc9bdba7bd16b1d6e427c8 32008 xserver-xorg-video-all_7.5+8+squeeze1_i386.deb c1ed5393568e1e4326594521c25779b2e0ba0e17 31856 xserver-xorg-input-all_7.5+8+squeeze1_i386.deb 2255b58412feaf47096328a68fd1e7860301f9a6 32498 xorg_7.5+8+squeeze1_i386.deb Checksums-Sha256: 3f99df1595d94e55292ebbb41a0795a7473231af3409a485d0ff157c2afac3e7 53334 xserver-xorg_7.5+8+squeeze1_i386.deb c686687d077c18da71523fcd2c49ccc62818894767b3df809e9e4a01de3b558a 32008 xserver-xorg-video-all_7.5+8+squeeze1_i386.deb 86639fbbe199c0f14515b9349a8f89486cbfdc0e09471060cfb6791788f00869 31856 xserver-xorg-input-all_7.5+8+squeeze1_i386.deb 6001098ce0923f7993d1e3e5e9f71f0ead394c30038de4eab4199da1fdc8c83d 32498 xorg_7.5+8+squeeze1_i386.deb Files: 38bcf0761c730045eeca4166defdb891 53334 x11 optional xserver-xorg_7.5+8+squeeze1_i386.deb 75d999aac19c5620701a5f0cba31c17b 32008 x11 optional xserver-xorg-video-all_7.5+8+squeeze1_i386.deb b23992e3095120e8afd6ec00f5125a30 31856 x11 optional xserver-xorg-input-all_7.5+8+squeeze1_i386.deb b06252421f449fa40054c303fc16fd63 32498 x11 optional xorg_7.5+8+squeeze1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJO655iAAoJECkckSfIPUEs4sQQAJpICdXB996bZLLWshqrXdsm Z9Ffs6ADtkeBh6Uwx0WrR1/8599RJYM2k6N+t4W0snTIE6JaFF9Kw8645z0vrpFl APvFl5fqmPoRQw82QTEMCzyY35OPvSYT1mQQeIAJSIzWmeAaLL10f4lc0ij7JsjM 62/F0PK36REy+fw3RwHk0n7fsNQCrKohDYH03mJUm/SZnQGAlN62qlEHl36esX6u 6kkRggnaRC/53NP8AReKr+LEu7dXcBkMKZRIQY+5g52hHxdeKEiAWYi6esdhpLhN YH0EcpfgyUDW3o0Gij6CQ4dyu0B0lzXXE4OHJW074mZJQUWGMUdAlxgNzVgtXaHF 0fmT9AzAI+9hq9TUU5FkjGCfrLxCY0sQwYDcOuuO+4lvlIqg+dM12SMTgf8pwqq0 jIpVca9Xxmex5xbsGzbvsBgcUIh9+/hoIoVgaHOPyMf6e4UJbFM3CDBZ5MYIrDBY 65dEbKhEtzTi4LC7sxSNh4UVKawjgALD6bVnDuSE9OTebjZCjBxU9OJZDcoFovVI jYmjxDxZ5+WDeycM+8cBgT0x0RRJaoU6CTamosmd04MgXQREe+Ug97XURoBUs97d iZzqA2L2ZrddJwRNH5hAcD7T+TyyBBCv6d0AKf7wE4+V9symNBGSzGq4Y7TWiF7H 97wxE5ekpytglIrxogJ/ =W5Rx -----END PGP SIGNATURE-----