Accepted libgd2 2.0.33-4ubuntu2.1 (source)

Ubuntu Installer archive at ubuntu.com
Tue Jun 12 00:55:19 BST 2007


Accepted:
 OK: libgd2_2.0.33-4ubuntu2.1.dsc
     -> Component: main Section: oldlibs
 OK: libgd2_2.0.33-4ubuntu2.1.diff.gz

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Mon, 11 Jun 2007 14:43:06 -0700
Source: libgd2
Binary: libgd2-noxpm-dev libgd2-noxpm libgd2-xpm libgd2-xpm-dev libgd-tools
Architecture: source
Version: 2.0.33-4ubuntu2.1
Distribution: edgy-security
Urgency: low
Maintainer: Jonas Smedegaard <dr at jones.dk>
Changed-By: Kees Cook <kees at ubuntu.com>
Description: 
 libgd-tools - GD command line tools and example code
 libgd2-noxpm - GD Graphics Library version 2 (without XPM support)
 libgd2-noxpm-dev - GD Graphics Library version 2 (development version)
 libgd2-xpm - GD Graphics Library version 2
 libgd2-xpm-dev - GD Graphics Library version 2 (development version)
Changes: 
 libgd2 (2.0.33-4ubuntu2.1) edgy-security; urgency=low
 .
   * SECURITY UPDATE: memory leak via font manipulation, endless loop via PNG.
   * Add 1007_png_endless_loop.patch: abort on corrupted PNGs.
     - upstream fixes backported
     - CVE-2007-2756
   * Add 1008_font_double_increment.patch: detect end of string correctly.
     - upstream fixes backported
     - CVE-2007-0455
Files: 
 077d1a11e3b050e53d896301d3b87e04 955 libs optional libgd2_2.0.33-4ubuntu2.1.dsc
 65f45c16574bc9376de4e618d699947c 264583 libs optional libgd2_2.0.33-4ubuntu2.1.diff.gz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFGbcguH/9LqRcGPm0RAoBGAJ497yBBxeapgIJ6kYTMSR+YRBrxzgCfWoqh
Ol4d2VE1v8fwSTHMdfyhCjg=
=xhKa
-----END PGP SIGNATURE-----





More information about the edgy-changes mailing list