[ubuntu/natty-security] libxfont 1:1.4.3-2ubuntu0.1 (Accepted)
Marc Deslauriers
marc.deslauriers at ubuntu.com
Mon Aug 15 13:03:28 UTC 2011
libxfont (1:1.4.3-2ubuntu0.1) natty-security; urgency=low
* SECURITY UPDATE: arbitrary code execution via overflow
- debian/patches/CVE-2011-2895.patch: check remaining length in
src/fontfile/decompress.c.
- CVE-2011-2895
Date: Thu, 11 Aug 2011 10:23:56 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/natty/+source/libxfont/1:1.4.3-2ubuntu0.1
-------------- next part --------------
Format: 1.8
Date: Thu, 11 Aug 2011 10:23:56 -0400
Source: libxfont
Binary: libxfont1 libxfont1-udeb libxfont1-dbg libxfont-dev
Architecture: source
Version: 1:1.4.3-2ubuntu0.1
Distribution: natty-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
libxfont-dev - X11 font rasterisation library (development headers)
libxfont1 - X11 font rasterisation library
libxfont1-dbg - X11 font rasterisation library (debug package)
libxfont1-udeb - X11 font rasterisation library (udeb)
Changes:
libxfont (1:1.4.3-2ubuntu0.1) natty-security; urgency=low
.
* SECURITY UPDATE: arbitrary code execution via overflow
- debian/patches/CVE-2011-2895.patch: check remaining length in
src/fontfile/decompress.c.
- CVE-2011-2895
Checksums-Sha1:
248799c3ac9abaeb43cd66a5620dc1d70d306bfc 2250 libxfont_1.4.3-2ubuntu0.1.dsc
b9bd546b74136b2c75ccc380e8ecdb6759978d14 19180 libxfont_1.4.3-2ubuntu0.1.diff.gz
Checksums-Sha256:
0fe090bea0054b7f9a25229a3d9f425d24f9ecec4bee341c453ef5bfe190358b 2250 libxfont_1.4.3-2ubuntu0.1.dsc
92eb0afc04f1e610e86bf54981f8c84f2c4664308e37985287cc3bb611c42223 19180 libxfont_1.4.3-2ubuntu0.1.diff.gz
Files:
39b2fbafe24736997c4f90b68fdce55a 2250 x11 optional libxfont_1.4.3-2ubuntu0.1.dsc
62e746454bc3cef3a94991195757ef29 19180 x11 optional libxfont_1.4.3-2ubuntu0.1.diff.gz
Original-Maintainer: Debian X Strike Force <debian-x at lists.debian.org>
More information about the Natty-changes
mailing list