lcms 1.13-1ubuntu0.2 source package in Ubuntu

Changelog

lcms (1.13-1ubuntu0.2) dapper-security; urgency=low

  * SECURITY UPDATE: Denial of service via large memory leak
    - properly free memory in src/cmsio1.c.
    - CVE-2009-0581
  * SECURITY UPDATE: Arbitrary code execution due to integer overflows
    - add new alloc functions in include/lcms.h and fix overflows in
      src/cmsgamma.c, src/cmsio1.c and src/cmslut.c.
    - CVE-2009-0723
  * SECURITY UPDATE: Arbitrary code execution due to buffer overflow
    - add validateNewLUT() and use in src/cmsio1.c and src/cmslut.c.
    - CVE-2009-0733

 -- Marc Deslauriers <email address hidden>   Sat, 21 Mar 2009 18:43:48 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Dapper
Original maintainer:
Shiju
Architectures:
any
Section:
libs
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
lcms_1.13.orig.tar.gz 572.0 KiB c8370e796e17bf88ecbc2ed7f9fb5c81c91398db342cd4097e8bc6e5b18f8e8d
lcms_1.13-1ubuntu0.2.diff.gz 16.0 KiB accc235e0d95d0db2b5781d6a680973ef9cab1e5005ba1ef8410edeafdfeb800
lcms_1.13-1ubuntu0.2.dsc 647 bytes 82e6cac9c7ec29e8327769900d7a4f8d3eba238f4c24f1b2ead823b6a67556d5

View changes file

Binary packages built by this source

liblcms-utils: No summary available for liblcms-utils in ubuntu dapper.

No description available for liblcms-utils in ubuntu dapper.

liblcms1: No summary available for liblcms1 in ubuntu dapper.

No description available for liblcms1 in ubuntu dapper.

liblcms1-dev: No summary available for liblcms1-dev in ubuntu dapper.

No description available for liblcms1-dev in ubuntu dapper.