[ubuntu/vivid-proposed] graphviz 2.38.0-6ubuntu1 (Accepted)
Seth Arnold
seth.arnold at canonical.com
Tue Dec 9 14:47:15 UTC 2014
graphviz (2.38.0-6ubuntu1) vivid; urgency=medium
* SECURITY UPDATE: Format string vulnerability may allow attackers to
cause a denial of service or possibly execute code.
- debian/patches/CVE-2014-9157.patch: Fix format string vulnerability in
lib/cgraph/scan.l yyerror() routine.
- CVE-2014-9157
Date: Thu, 04 Dec 2014 16:03:32 -0800
Changed-By: Seth Arnold <seth.arnold at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/graphviz/2.38.0-6ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 04 Dec 2014 16:03:32 -0800
Source: graphviz
Binary: graphviz libgv-guile libgv-lua libgv-perl libgv-php5 libgv-python libgv-ruby libgv-tcl libcgraph6 libcdt5 libpathplan4 libgvc6 libgvc6-plugins-gtk libgvpr2 libxdot4 libgraphviz-dev graphviz-doc graphviz-dev
Architecture: source
Version: 2.38.0-6ubuntu1
Distribution: vivid
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Seth Arnold <seth.arnold at canonical.com>
Description:
graphviz - rich set of graph drawing tools
graphviz-dev - transitional package for graphviz-dev rename
graphviz-doc - additional documentation for graphviz
libcdt5 - rich set of graph drawing tools - cdt library
libcgraph6 - rich set of graph drawing tools - cgraph library
libgraphviz-dev - graphviz libs and headers against which to build applications
libgv-guile - Guile bindings for graphviz
libgv-lua - Lua bindings for graphviz
libgv-perl - Perl bindings for graphviz
libgv-php5 - PHP5 bindings for graphviz
libgv-python - Python bindings for graphviz
libgv-ruby - Ruby bindings for graphviz
libgv-tcl - Tcl bindings for graphviz
libgvc6 - rich set of graph drawing tools - gvc library
libgvc6-plugins-gtk - rich set of graph drawing tools - gtk plugins
libgvpr2 - rich set of graph drawing tools - gvpr library
libpathplan4 - rich set of graph drawing tools - pathplan library
libxdot4 - rich set of graph drawing tools - xdot library
Changes:
graphviz (2.38.0-6ubuntu1) vivid; urgency=medium
.
* SECURITY UPDATE: Format string vulnerability may allow attackers to
cause a denial of service or possibly execute code.
- debian/patches/CVE-2014-9157.patch: Fix format string vulnerability in
lib/cgraph/scan.l yyerror() routine.
- CVE-2014-9157
Checksums-Sha1:
4901564eb62e136f6ce4bd901403ec34f7a14bd0 3373 graphviz_2.38.0-6ubuntu1.dsc
7937a09a87570bc0171178308fc5addbdf0e7a54 44244 graphviz_2.38.0-6ubuntu1.debian.tar.xz
Checksums-Sha256:
edbba514690f401592c01c5217ba776f50d3d7d816b6f83e445335f033d995c3 3373 graphviz_2.38.0-6ubuntu1.dsc
64e1a3dd1285a680ee4d1ff51917f32f5839fda8f5a81a91e103fd4f6f33c9df 44244 graphviz_2.38.0-6ubuntu1.debian.tar.xz
Files:
ed6c264f0f1890d71709980d9e508389 3373 graphics optional graphviz_2.38.0-6ubuntu1.dsc
508c7fb42b3dd964d9e44e7a8903298d 44244 graphics optional graphviz_2.38.0-6ubuntu1.debian.tar.xz
Original-Maintainer: Debian QA Group <packages at qa.debian.org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUhwmIAAoJEGVp2FWnRL6THZAP/3Bk7DMienkzNdD/CRu4eFj/
MUPoazq2MV+4S2lY/k68YyWETrxQ0ljZCQsJmzxnc0/+Ps83xsMVmjPxDZFYiaTQ
qjicyCZfZgiUU/E1KkPPuJRCEo2jGJw6pnAJmtE+hjlNPE7rHKB2dCQtfNEsAWJU
bsiXufDRVzGV6jzmuOGLBeEZHOJO/lulbWzAHGcH/hroyERjpZOB3JFpAQAU0mor
l/65YkUMZsztEu6jx1RIkwHbGALXecq0AE7bqFgkiJvILIobD1ReWoaPbR8PT2m7
ycmnTA87QBDIfcgMIrDIZe2675+pVxNaLkGXbcG2tbJarr0kXccF7crcmNyYqwE7
5ueIBfcT5rPfdVlvY1bMUPgvnH9HPhoWIhi1SLQcofQm8Yx6diQedf5cPaopbeLA
VigyZ34h3wagfxFcKYEnmCBYPQrVci5V8Lx6r6B4UQpxjOfL10WgIOK7cuW+t3HM
TVYZ72pLPRkb3r9BKdWy4g0dVZKH+XJSSgraq+1Xg3eCxlryzV56ZA26GcBn6BwV
hXGFAgtzf2Q3lR7NVPQRU6rHogvzJIiukROo2pdMp7m6G6mMdpsvss0jfD+pWu9p
rcdLAJ7CsGDrT+nSktRx93DIYGWvd71QDjRHxDzz8KUv81aIGasq0xoH9DNYfjuL
A0YpE9pMKU9LWa27Y9mo
=1nkh
-----END PGP SIGNATURE-----
More information about the Vivid-changes
mailing list