New Debian xterm 327-2+deb9u3 fixes: This update addresses the following issue: * Buffer overflow in set_sixel in graphics_sixel.c (CVE-2022-24130)
--- mirror/ftp/4.4/unmaintained/4.4-8/source/xterm_327-2+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/xterm_327-2+deb9u3.dsc @@ -1,3 +1,16 @@ +327-2+deb9u3 [Sun, 06 Feb 2022 22:41:24 +0530] Utkarsh Gupta <utkarsh@debian.org>: + + * Non-maintainer upload by the LTS team. + * Add patch to check for out-of-bounds condition while drawing + sixels, and quit that operation (reported by Nick Black). + (Fixes: CVE-2022-24130) (Closes: #1004689) + +327-2+deb9u2 [Sat, 20 Mar 2021 09:05:15 +0530] Utkarsh Gupta <utkarsh@debian.org>: + + * Non-maintainer upload by the LTS team. + * Revert the extra changes in the CVE-2021-27135's patch + since it caused unnecessary regression. (Closes: #984615) + 327-2+deb9u1 [Sat, 13 Feb 2021 22:21:27 +0530] Utkarsh Gupta <utkarsh@debian.org>: * Non-maintainer upload by the LTS team. <http://piuparts.knut.univention.de/4.4-8/#3641025452569259452>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] b2cb5634e9 Bug #54428: xterm 327-2+deb9u3 doc/errata/staging/xterm.yaml | 12 ++++++++++++ 1 file changed, 12 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1174>