diff -Nru tigervnc-1.12.0+dfsg/debian/changelog tigervnc-1.12.0+dfsg/debian/changelog --- tigervnc-1.12.0+dfsg/debian/changelog 2022-03-25 17:06:01.000000000 +0000 +++ tigervnc-1.12.0+dfsg/debian/changelog 2024-01-23 19:20:24.000000000 +0000 @@ -1,3 +1,11 @@ +tigervnc (1.12.0+dfsg-4ubuntu0.22.04.1) jammy; urgency=medium + + * SECURITY UPDATE: Enforce building of TigerVNC against a version of + xorg-server-source that is not vulnerable to CVE-2023-1393. + (LP: #2048442) + + -- Aaron Rainbolt Tue, 23 Jan 2024 19:20:24 +0000 + tigervnc (1.12.0+dfsg-4) unstable; urgency=medium * Backported a Debian change applied upstream that provides app stream diff -Nru tigervnc-1.12.0+dfsg/debian/control tigervnc-1.12.0+dfsg/debian/control --- tigervnc-1.12.0+dfsg/debian/control 2022-03-25 10:17:14.000000000 +0000 +++ tigervnc-1.12.0+dfsg/debian/control 2024-01-23 19:11:43.000000000 +0000 @@ -1,7 +1,8 @@ Source: tigervnc Section: x11 Priority: optional -Maintainer: TigerVNC Packaging Team +XSBC-Original-Maintainer: TigerVNC Packaging Team +Maintainer: Ubuntu Developers Uploaders: Joachim Falk , Mike Gabriel , @@ -27,7 +28,7 @@ libxdamage-dev, libwrap0-dev, libfltk1.3-dev (>= 1.3.3), - xorg-server-source (>= 2:21), + xorg-server-source (>= 2:21.1.3-2ubuntu2.9), xserver-xorg-dev, appstream, # this are dependencies from xorg-server-21.1.3 source deb