[ubuntu/jammy-updates] rlottie 0.1+dfsg-2ubuntu0.1 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Thu Jan 9 20:58:10 UTC 2025


rlottie (0.1+dfsg-2ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Stack-based buffer overflow patch was incomplete
    - debian/patches/Check-buffer-length.patch: Amend patch to properly
      check buffer bounds in the src/vector/vrle.cpp blit function
      and its variants.
    - CVE-2021-31315
  * SECURITY UPDATE: Stack-based buffer overflow patch was incomplete
    - debian/patches/Freetype-raster.patch: Amend patch to correctly
      check return conditions in the gray_render_cubic function and also
      check the number of ycells in the gray_find_cell function of
      src/vector/freetype/v_ft_raster.cpp.
    - CVE-2021-31321
  * debian/rules: Use compiler flag for level 2 optimization (-O2)
    instead of level 3 (-O3) on ppc64el architectures. Level 3
    optimization can lead to build errors due to memory alignment
    requirements.

Date: 2024-12-19 18:37:11.139774+00:00
Changed-By: nicolas campuzano jimenez <nicolas.campuzano at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/rlottie/0.1+dfsg-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list