ghostscript 8.71.dfsg.1-0ubuntu5.4 source package in Ubuntu

Changelog

ghostscript (8.71.dfsg.1-0ubuntu5.4) lucid-security; urgency=low

  * SECURITY UPDATE: integer overflows via integer multiplication for
    memory allocation
    - debian/patches/CVE-2008-352x.dpatch: introduce new size-checked
      allocation functions and use them in:
      * jasper/src/libjasper/base/{jas_cm.c,jas_icc.c,jas_image.c,
        jas_malloc.c,jas_seq.c}
      * jasper/src/libjasper/bmp/bmp_dec.c
      * jasper/src/libjasper/include/jasper/jas_malloc.h
      * jasper/src/libjasper/jp2/{jp2_cod.c,jp2_dec.c,jp2_enc.c}
      * jasper/src/libjasper/jpc/{jpc_cs.c,jpc_dec.c,jpc_enc.c,jpc_mqdec.c,
        jpc_mqenc.c,jpc_qmfb.c,jpc_t1enc.c,jpc_t2cod.c,jpc_t2dec.c,
        jpc_t2enc.c,jpc_tagtree.c,jpc_util.c}
      * jasper/src/libjasper/mif/mif_cod.c
    - CVE-2008-3520
  * SECURITY UPDATE: buffer overflow via vsprintf in jas_stream_printf()
    - debian/patches/CVE-2008-352x.dpatch: use vsnprintf() in
      jasper/src/libjasper/base/jas_stream.c
    - CVE-2008-3522
  * SECURITY UPDATE: denial of service and possible code execution via
    heap-based buffer overflows.
    - debian/patches/CVE-2011-451x.dpatch: validate compparms->numrlvls
      and allocate proper size in jasper/src/libjasper/jpc/jpc_cs.c.
    - CVE-2011-4516
    - CVE-2011-4517
 -- Marc Deslauriers <email address hidden>   Tue, 20 Dec 2011 15:44:19 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Lucid
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
text
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ghostscript_8.71.dfsg.1.orig.tar.gz 20.2 MiB bea84ec26a63faf2f7a2208416c9baf7bb6dfb4a3d4a02abc0ed1988775f3e9b
ghostscript_8.71.dfsg.1-0ubuntu5.4.diff.gz 71.0 KiB aef08938e8800451c7cbbbae17e511e2259aa17de55052171bc1bdaf2d60d846
ghostscript_8.71.dfsg.1-0ubuntu5.4.dsc 2.4 KiB 9298bd2ab2fe94fc4805a0d20adc48586d60069aad4a8f0e283840c2bb367f3c

View changes file

Binary packages built by this source

ghostscript: No summary available for ghostscript in ubuntu lucid.

No description available for ghostscript in ubuntu lucid.

ghostscript-cups: No summary available for ghostscript-cups in ubuntu lucid.

No description available for ghostscript-cups in ubuntu lucid.

ghostscript-doc: No summary available for ghostscript-doc in ubuntu lucid.

No description available for ghostscript-doc in ubuntu lucid.

ghostscript-x: No summary available for ghostscript-x in ubuntu lucid.

No description available for ghostscript-x in ubuntu lucid.

gs: No summary available for gs in ubuntu lucid.

No description available for gs in ubuntu lucid.

gs-aladdin: No summary available for gs-aladdin in ubuntu lucid.

No description available for gs-aladdin in ubuntu lucid.

gs-common: No summary available for gs-common in ubuntu lucid.

No description available for gs-common in ubuntu lucid.

gs-esp: No summary available for gs-esp in ubuntu lucid.

No description available for gs-esp in ubuntu lucid.

gs-esp-x: No summary available for gs-esp-x in ubuntu lucid.

No description available for gs-esp-x in ubuntu lucid.

gs-gpl: No summary available for gs-gpl in ubuntu lucid.

No description available for gs-gpl in ubuntu lucid.

libgs-dev: No summary available for libgs-dev in ubuntu lucid.

No description available for libgs-dev in ubuntu lucid.

libgs-esp-dev: No summary available for libgs-esp-dev in ubuntu lucid.

No description available for libgs-esp-dev in ubuntu lucid.

libgs8: No summary available for libgs8 in ubuntu lucid.

No description available for libgs8 in ubuntu lucid.