[ubuntu/lucid-security] libxfont 1:1.4.1-1ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Mon Aug 15 13:04:07 UTC 2011


libxfont (1:1.4.1-1ubuntu0.1) lucid-security; urgency=low

  * SECURITY UPDATE: arbitrary code execution via overflow
    - debian/patches/CVE-2011-2895.patch: check remaining length in
      src/fontfile/decompress.c.
    - CVE-2011-2895

Date: Thu, 11 Aug 2011 10:31:45 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/lucid/+source/libxfont/1:1.4.1-1ubuntu0.1
-------------- next part --------------
Format: 1.8
Date: Thu, 11 Aug 2011 10:31:45 -0400
Source: libxfont
Binary: libxfont1 libxfont1-dbg libxfont-dev
Architecture: source
Version: 1:1.4.1-1ubuntu0.1
Distribution: lucid-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 libxfont-dev - X11 font rasterisation library (development headers)
 libxfont1  - X11 font rasterisation library
 libxfont1-dbg - X11 font rasterisation library (debug package)
Changes: 
 libxfont (1:1.4.1-1ubuntu0.1) lucid-security; urgency=low
 .
   * SECURITY UPDATE: arbitrary code execution via overflow
     - debian/patches/CVE-2011-2895.patch: check remaining length in
       src/fontfile/decompress.c.
     - CVE-2011-2895
Checksums-Sha1: 
 e41af1275cd36c92a2b4bc3be8d8f8e2f7939fcd 2192 libxfont_1.4.1-1ubuntu0.1.dsc
 b1d2a8306566af4321f5612953d1dcf7176bef27 18751 libxfont_1.4.1-1ubuntu0.1.diff.gz
Checksums-Sha256: 
 59127bbdff481c3898a8357f0e18153f9146c9054f605b133e520d85f0799861 2192 libxfont_1.4.1-1ubuntu0.1.dsc
 e7fb83dbfa7dd90031dd5cd9cc237ed029c222caf07be8fa25fd1d97cb840f83 18751 libxfont_1.4.1-1ubuntu0.1.diff.gz
Files: 
 2a39435b8e1fca928fd3f788efacb681 2192 x11 optional libxfont_1.4.1-1ubuntu0.1.dsc
 49194bd60f921b7c55741b037e77b1a7 18751 x11 optional libxfont_1.4.1-1ubuntu0.1.diff.gz
Original-Maintainer: Debian X Strike Force <debian-x at lists.debian.org>


More information about the Lucid-changes mailing list