Univention Bugzilla – Bug 54378
libxfont: Multiple issues (4.4)
Last modified: 2022-01-26 16:57:49 CET
New Debian libxfont 1:2.0.1-3+deb9u2 fixes: This update addresses the following issue: * User can trigger arbitrary file read by X server causing a DoS (CVE-2017-16611)
--- mirror/ftp/4.3/unmaintained/4.3-0/source/libxfont_2.0.1-3+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/libxfont_2.0.1-3+deb9u2.dsc @@ -1,3 +1,9 @@ +1:2.0.1-3+deb9u2 [Tue, 25 Jan 2022 18:03:02 +0100] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the LTS Team. + * CVE-2017-16611 + Open files with O_NOFOLLOW + 1:2.0.1-3+deb9u1 [Fri, 06 Oct 2017 22:26:19 +0200] Julien Cristau <jcristau@debian.org>: * Check for end of string in PatternMatch (CVE-2017-13720) <http://piuparts.knut.univention.de/4.4-8/#3679793506649388939>
OK: yaml OK: announce_errata OK: patch OK: piuparts
<https://errata.software-univention.de/#/?erratum=4.4x1160>