ChangeLog for: 2024-04-03 23:22:06
l/PyQt-builder-1.16.0-x86_64-1.txz: Upgraded.
l/gst-plugins-bad-free-1.24.1-x86_64-2.txz: Rebuilt.
Recompiled against aom-3.8.2 to build libgstaom.so.
l/nodejs-20.12.1-x86_64-1.txz: Upgraded.
l/python-lxml-5.2.1-x86_64-1.txz: Upgraded.
x/xorg-server-21.1.12-x86_64-1.txz: Upgraded.
This update fixes security issues:
Heap buffer overread/data leakage in ProcXIGetSelectedEvents.
Heap buffer overread/data leakage in ProcXIPassiveGrabDevice.
Heap buffer overread/data leakage in ProcAppleDRICreatePixmap.
Use-after-free in ProcRenderAddGlyphs.
For more information, see:
https://lists.x.org/archives/xorg-announce/2024-April/003497.html
https://www.cve.org/CVERecord?id=CVE-2024-31080
https://www.cve.org/CVERecord?id=CVE-2024-31081
https://www.cve.org/CVERecord?id=CVE-2024-31082
https://www.cve.org/CVERecord?id=CVE-2024-31083
(* Security fix *)
x/xorg-server-xephyr-21.1.12-x86_64-1.txz: Upgraded.
x/xorg-server-xnest-21.1.12-x86_64-1.txz: Upgraded.
x/xorg-server-xvfb-21.1.12-x86_64-1.txz: Upgraded.
x/xorg-server-xwayland-23.2.5-x86_64-1.txz: Upgraded.
This update fixes security issues:
Heap buffer overread/data leakage in ProcXIGetSelectedEvents.
Heap buffer overread/data leakage in ProcXIPassiveGrabDevice.
Use-after-free in ProcRenderAddGlyphs.
For more information, see:
https://lists.x.org/archives/xorg-announce/2024-April/003497.html
https://www.cve.org/CVERecord?id=CVE-2024-31080
https://www.cve.org/CVERecord?id=CVE-2024-31081
https://www.cve.org/CVERecord?id=CVE-2024-31083
(* Security fix *)