[ubuntu/natty-security] t1lib 5.1.2-3ubuntu0.11.04.2 (Accepted)

Jamie Strandboge jamie at ubuntu.com
Thu Jan 19 17:33:58 UTC 2012


t1lib (5.1.2-3ubuntu0.11.04.2) natty-security; urgency=low

  * SECURITY UPDATE: fix denial of service via oversized fonts
    - debian/patches/CVE-2011-1552_1553_1554.patch: add additional tests to
      address remaining crashes
    - CVE-2011-1552
    - CVE-2011-1553
    - CVE-2011-1554
  * SECURITY UPDATE: fix heap-based buffer overflow via AFM font parser
    - debian/patches/CVE-2010-2642_2011-0433.patch: verify array boundaries in
      lib/t1lib/parseAFM.c
    - CVE-2010-2642
    - CVE-2011-0433

Date: Tue, 17 Jan 2012 14:35:45 -0600
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/natty/+source/t1lib/5.1.2-3ubuntu0.11.04.2
-------------- next part --------------
Format: 1.8
Date: Tue, 17 Jan 2012 14:35:45 -0600
Source: t1lib
Binary: libt1-5 libt1-dev t1lib-bin libt1-doc libt1-5-dbg
Architecture: source
Version: 5.1.2-3ubuntu0.11.04.2
Distribution: natty-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Jamie Strandboge <jamie at ubuntu.com>
Description: 
 libt1-5    - Type 1 font rasterizer library - runtime
 libt1-5-dbg - Type 1 font rasterizer library - debugging runtime
 libt1-dev  - Type 1 font rasterizer library - development
 libt1-doc  - Type 1 font rasterizer library - developers documentation
 t1lib-bin  - Type 1 font rasterizer library - user binaries
Changes: 
 t1lib (5.1.2-3ubuntu0.11.04.2) natty-security; urgency=low
 .
   * SECURITY UPDATE: fix denial of service via oversized fonts
     - debian/patches/CVE-2011-1552_1553_1554.patch: add additional tests to
       address remaining crashes
     - CVE-2011-1552
     - CVE-2011-1553
     - CVE-2011-1554
   * SECURITY UPDATE: fix heap-based buffer overflow via AFM font parser
     - debian/patches/CVE-2010-2642_2011-0433.patch: verify array boundaries in
       lib/t1lib/parseAFM.c
     - CVE-2010-2642
     - CVE-2011-0433
Checksums-Sha1: 
 61510d6351bac659ab62643ec1144e619e62472c 1906 t1lib_5.1.2-3ubuntu0.11.04.2.dsc
 8ae8ed4dbe0c677b50399b9e31e270d63d15658a 20432 t1lib_5.1.2-3ubuntu0.11.04.2.diff.gz
Checksums-Sha256: 
 e6f80243709aebd1edc0b38fce27d84955dc85dfe9533903d331d3a2bce879ef 1906 t1lib_5.1.2-3ubuntu0.11.04.2.dsc
 a3c0bbe4fbcda95ed7aa9896a59b004101b6fe7dde0435942a77a8646193794f 20432 t1lib_5.1.2-3ubuntu0.11.04.2.diff.gz
Files: 
 401adcab21c35839ac6e4aef198dc1d0 1906 libs optional t1lib_5.1.2-3ubuntu0.11.04.2.dsc
 aa4c14ece0d0dc4a79ead35e46a59eed 20432 libs optional t1lib_5.1.2-3ubuntu0.11.04.2.diff.gz
Original-Maintainer: Ruben Molina <rmolina at udea.edu.co>


More information about the Natty-changes mailing list