| Summary: | media-libs/netpbm includes vulnerable libjasper code (CVE-2007-2721) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Pierre-Yves Rofes (RETIRED) <py> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED INVALID | ||
| Severity: | minor | CC: | graphics+disabled |
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://secunia.com/advisories/27489/ | ||
| Whiteboard: | B3 [ebuild] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
Pierre-Yves Rofes (RETIRED)
2007-11-08 22:09:36 UTC
patch is in /usr/portage/media-libs/jasper/files/jasper-overflow-fix.patch Only change is "uint_fast16_t" replaced with "uint_fast32_t", but apart from that it should apply just fine. Graphics, please provide a fixed ebuild. netpbm forces external jasper linking like any correct package should if you find that's not the case, let me know |