Closed grahamc closed 7 years ago
I'd personally wait for a bit with Xorg vulns. – until upstream pushes fixes. They tend to provide a detailed advisory page and release minor bumps fast. (Feel free to hand-patch before that.)
We already have a fixed version packaged.
Here is a report from the oss-security mailing list for Vulnerability Roundup 27.
Skip to First Email
Instructions:
Identification
Identify if we have the software, in 16.09, 17.03, and unstable. Then determine if we are vulnerable, and make a comment with your findings. It can also be helpful to specify if you think there is a patch, or if it can be fixed via a general update.
Example:
IMPORTANT: If you believe there are possibly related issues, bring them up on the parent issue!
Patching
Start by commenting on this issue saying you're working on a patch. This way, we don't duplicate work.
If you open a pull request, tag this issue and the master issue for the roundup.
If you commit the patch directly to a branch, please leave a comment on this issue with the branch and the commit hash, example:
Skip to First Email
Upon Completion ...
Info
Triage Indicator:
Should the search term be changed from
xorg
? Suggest a new package search by commenting:Known CVEs: CVE-2017-2624, CVE-2017-2625, CVE-2017-2626
Skip to End
Tue, 28 Feb 2017 14:39:18 +0100 X41 D-Sec GmbH Advisories,
02cb8961-7fc2-7f7f-4924-40c5c8f61829@x41-dsec.de
signature.asc
-----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEpwxVTgxAIcUvTugIo5Klpg50CxAFAli1fYYACgkQo5Klpg50 CxDntA/+IUm8N0T3sPcvR7uZnLbweQv35IbBdC1ntPYHHx/zmuzDPzfUXhSvDSkT UYVcwHiSdo2t7h8jD7Ctqm3qSovG7wEZU7nfrE778jlPHSYos/godGnuXonF6SLN EDA80uVH4ePz2/OYkXDhehbKaA+LBcFBxTt6pv92MU2AvHEQaVruyKrXN2RdlQH5 bVzIznJJQWsRJdoKYzyNayZ7TQMVMqcqpbnx5CchvmmY5TZYg7m3qbiVahPTrQz6 EOwlgfPB/6rOaMODxCAAKipeidVPXuRKE/JWFyDdp/2X/74uT5Lt3JK5qBVJEGKM V+UBGi17vcr19wMrmU9JVQQXFCRfxKuMi7tclMuYAJqMWxpuup6xXLcbvsC0vt4n 2fWOWuQd9+uSbr4QEtv4mdEx3KCmjorax1hnLZXGyEPEKiUHFWfeM9naEAPX18HD hQJa7m9/a3lM2mz4FGo3+WgspKQlEczJhevw3KCA3CYa4pdKGcf9gbb1QcS3LNea pe0/FwJ+JXoH5MZ9EerHjZ08bKFNFcDI5JJCtS+L3Z9xx84/kHg7zttbwEp3K386 eMTkk7AOgE6i75y6D0P2TibnZtBTOduuDd8v4Ws/4zByeK6z/QD0AJA/RV1Cw0bn agoJCoaigfNZpigM/dGMZf/sF9Dt2U/qBWhXgVk583MeODjqpOg= =zMry -----END PGP SIGNATURE-----Skip to End