Debian Security Advisory

DSA-3160-1 xorg-server -- security update

Date Reported:
11 Feb 2015
Affected Packages:
xorg-server
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-0255.
More information:

Olivier Fourdan discovered that missing input validation in the Xserver's handling of XkbSetGeometry requests may result in an information leak or denial of service.

For the stable distribution (wheezy), this problem has been fixed in version 2:1.12.4-6+deb7u6.

For the unstable distribution (sid), this problem has been fixed in version 2:1.16.4-1.

We recommend that you upgrade your xorg-server packages.