Summary: | media-libs/giflib: buffer overflow / null pointer deref | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Thierry Carrez (RETIRED) <koon> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | ||
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | A2 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Thierry Carrez (RETIRED)
![]() Mamoru: this is a semi-public issue, could you silently add 4.1.4 to the tree so that we are ready to disclose it by the coordinated date (2005/10/28, 1400 UTC) libungif is dead only giflib should be updated and libungif should be masked Release date is now set to 2005/11/03 CVE Ids : CVE-2005-2974 libungif NULL pointer deref CVE-2005-3350 libungif OOB access usata/vapier: please bump giflib-4.1.4 now in portage Ccing security liaisons... Please test and mark 4.1.4 stable, so that's the ebuild is ready at GLSA release time. Stable on ppc and hppa. Stable on alpha. amd64 stable sparc stable. Marked ppc64 stable (and urt) Adding halcyon to handle x86 stable marking. x86 stable Embargo ended, ready to send. mips should mark giflib-4.1.4 ~ ppc-macos should test and mark giflib-4.1.4 stable Hm. in fact mips should even test and mark stable. I had to stable the follow packages to stable giflib-4.1.4: urt-3.1b-r1 ghostscript-7.07.1-r10 media-fonts/gnu-gs-fonts-std-8.11 Note: I encountered bug #111455 but ignored it for now and stabled giflib. GLSA 200511-03 mips should mark stable to benefit from GLSA Stable on mips. |