X.Org Security Advisory: Security issue in the X server

2023-02-06 Thread Peter Hutterer
X.Org Security Advisory: February 07, 2023 Security issue in the X server == This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. * CVE-2023-0494/ZDI-CAN-19596: X

[ANNOUNCE] xorg-server 21.1.7

2023-02-06 Thread Peter Hutterer
xserver 21.1.7 is now available. This release contains the fix for CVE-2023-0494 in today's security advisory: https://lists.x.org/archives/xorg-announce/2023-February/003320.html It also fixes a second possible OOB access during EnqueueEvent and a crasher caused by ResourceClientBits not correctl