[ubuntu/wily-proposed] qt4-x11 4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Wed Jun 3 14:22:57 UTC 2015


qt4-x11 (4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7) wily; urgency=medium

  * SECURITY UPDATE: denial of service via crafted BMP
    - debian/patches/CVE-2015-0295.patch: fix division by zero in
      src/gui/image/qbmphandler.cpp.
    - CVE-2015-0295
  * SECURITY UPDATE: denial of service and possible code execution via
    crafted BMP or ICO images
    - debian/patches/CVE-2015-1858-1859.patch: move check to better
      location in src/gui/image/qbmphandler.cpp, check depth in
      src/plugins/imageformats/ico/qicohandler.cpp.
    - CVE-2015-1858
    - CVE-2015-1859
  * SECURITY UPDATE: denial of service and possible code exection via
    crafted GIF image
    - debian/patches/CVE-2015-1860.patch: check bounds in
      src/gui/image/qgifhandler.cpp.
    - CVE-2015-1860

Date: Wed, 03 Jun 2015 09:34:49 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 03 Jun 2015 09:34:49 -0400
Source: qt4-x11
Binary: libqtcore4 qtcore4-l10n libqt4-core libqtgui4 libqt4-gui libqt4-network libqt4-opengl libqt4-script libqt4-scripttools libqt4-sql libqt4-sql-mysql libqt4-sql-odbc libqt4-sql-psql libqt4-sql-sqlite libqt4-sql-tds libqt4-svg libqt4-webkit libqt4-xml libqt4-xmlpatterns libqt4-dbus libqtdbus4 libqt4-qt3support libqt4-designer libqt4-help libqt4-assistant libqt4-test libqt4-declarative libqt4-declarative-folderlistmodel libqt4-declarative-gestures libqt4-declarative-particles libqt4-declarative-shaders libqt4-dev libqt4-dev-bin libqt4-private-dev libqt4-opengl-dev libqt4-dbg libqt4-designer-dbg libqt4-qt3support-dbg libqt4-script-dbg libqt4-webkit-dbg libqt4-xmlpatterns-dbg qt4-bin-dbg qt4-demos-dbg qt4-designer qt4-dev-tools qt4-qmake qt4-qtconfig qt4-demos qt4-qmlviewer qt4-linguist-tools qdbus qt4-doc qt4-doc-html qt4-default
Architecture: source
Version: 4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7
Distribution: wily
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 libqt4-assistant - transitional package for Qt 4 assistant module
 libqt4-core - transitional package for Qt 4 core non-GUI runtime libraries
 libqt4-dbg - Qt 4 library debugging symbols
 libqt4-dbus - Qt 4 D-Bus module
 libqt4-declarative - Qt 4 Declarative module
 libqt4-declarative-folderlistmodel - Qt 4 folderlistmodel QML plugin
 libqt4-declarative-gestures - Qt 4 gestures QML plugin
 libqt4-declarative-particles - Qt 4 particles QML plugin
 libqt4-declarative-shaders - Qt 4 shaders QML plugin
 libqt4-designer - Qt 4 designer module
 libqt4-designer-dbg - Qt 4 designer library debugging symbols
 libqt4-dev - Qt 4 development files
 libqt4-dev-bin - Qt 4 development programs
 libqt4-gui - transitional package for Qt 4 GUI runtime libraries
 libqt4-help - Qt 4 help module
 libqt4-network - Qt 4 network module
 libqt4-opengl - Qt 4 OpenGL module
 libqt4-opengl-dev - Qt 4 OpenGL library development files
 libqt4-private-dev - Qt 4 private development files
 libqt4-qt3support - Qt 3 compatibility library for Qt 4
 libqt4-qt3support-dbg - Qt 3 compatibility library for Qt 4 debugging symbols
 libqt4-script - Qt 4 script module
 libqt4-script-dbg - Qt 4 script library debugging symbols
 libqt4-scripttools - Qt 4 script tools module
 libqt4-sql - Qt 4 SQL module
 libqt4-sql-mysql - Qt 4 MySQL database driver
 libqt4-sql-odbc - Qt 4 ODBC database driver
 libqt4-sql-psql - Qt 4 PostgreSQL database driver
 libqt4-sql-sqlite - Qt 4 SQLite 3 database driver
 libqt4-sql-tds - Qt 4 FreeTDS database driver
 libqt4-svg - Qt 4 SVG module
 libqt4-test - Qt 4 test module
 libqt4-webkit - transitional package for Qt 4 WebKit module
 libqt4-webkit-dbg - transitional package for Qt 4 WebKit debugging symbols
 libqt4-xml - Qt 4 XML module
 libqt4-xmlpatterns - Qt 4 XML patterns module
 libqt4-xmlpatterns-dbg - Qt 4 XML patterns library debugging symbols
 libqtcore4 - Qt 4 core module
 libqtdbus4 - Qt 4 D-Bus module library
 libqtgui4  - Qt 4 GUI module
 qdbus      - Qt 4 D-Bus tool
 qt4-bin-dbg - Qt 4 binaries debugging symbols
 qt4-default - Qt 4 development defaults package
 qt4-demos  - Qt 4 examples and demos
 qt4-demos-dbg - Qt 4 examples and demos debugging symbols
 qt4-designer - graphical designer for Qt 4 applications
 qt4-dev-tools - Qt 4 development tools
 qt4-doc    - Qt 4 API documentation
 qt4-doc-html - Qt 4 API documentation (HTML format)
 qt4-linguist-tools - Qt 4 Linguist tools
 qt4-qmake  - Qt 4 qmake Makefile generator tool
 qt4-qmlviewer - Qt 4 QML viewer
 qt4-qtconfig - Qt 4 configuration tool
 qtcore4-l10n - Qt 4 core module translations
Changes:
 qt4-x11 (4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7) wily; urgency=medium
 .
   * SECURITY UPDATE: denial of service via crafted BMP
     - debian/patches/CVE-2015-0295.patch: fix division by zero in
       src/gui/image/qbmphandler.cpp.
     - CVE-2015-0295
   * SECURITY UPDATE: denial of service and possible code execution via
     crafted BMP or ICO images
     - debian/patches/CVE-2015-1858-1859.patch: move check to better
       location in src/gui/image/qbmphandler.cpp, check depth in
       src/plugins/imageformats/ico/qicohandler.cpp.
     - CVE-2015-1858
     - CVE-2015-1859
   * SECURITY UPDATE: denial of service and possible code exection via
     crafted GIF image
     - debian/patches/CVE-2015-1860.patch: check bounds in
       src/gui/image/qgifhandler.cpp.
     - CVE-2015-1860
Checksums-Sha1:
 b64ad8c5f47a1f4ba54698ac59a341e92a450f93 6244 qt4-x11_4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7.dsc
 fe77931257a5f72a9da276a74060b5ad41d62138 375796 qt4-x11_4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7.debian.tar.xz
Checksums-Sha256:
 eb83dfb216c14c73011189dc08d98d0504aae0395c22727a649ab84b80f9eb47 6244 qt4-x11_4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7.dsc
 8eae44ff2af256a14a698edc97149f41b237462cd91333df11f0fc13701449e2 375796 qt4-x11_4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7.debian.tar.xz
Files:
 b95e163de44284ec3bdd7d473f3e2c09 6244 libs optional qt4-x11_4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7.dsc
 145e642eb0f7c1136706064159dbafa1 375796 libs optional qt4-x11_4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu7.debian.tar.xz
Original-Maintainer: Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde at lists.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJVbwxZAAoJEGVp2FWnRL6T4/cQALLbRPKI7dadgf8K3h78Jei3
UUMqFL16q+JJFpGM4IbAhEEpeqv+zYEKZsYeKAlBSmT8QpJv+odMmKOGP8fyhWJk
3eyHysz3ezp4+CbB3OCM11CauxKDrQqkNe9eZ+mGAapKMmEDP/EMhueiM+EEiHwt
6amJDNYc6MV7RnCPEjcPsuiwo2AkoVYXycvfePkwdw9KrpPWfRHEu5xpL/hJQHpL
/gQa+IEv05bdzd4Ci9nsALZVOJIlZI18ZgTZtFhGr8jGw/2zAHOK1puv9kWGEpNJ
8uQSYmPJq/mjlkHEyzWKrmpgtKKsGxuSHKzegA5bQIb9u6dYHmVuuxQ/uKBf0bpQ
TmmDmlc2pMUT5A9Ow+ULeoyjB2imFNxzNdXTvhGmz/wYMNbQtipfOe+/eustz7Uv
fS3rvsMki8lZaVwkOAtnOBSmV2DxTMKmEmN//EBkdNhmESRIP4UniNoNJYBYcc1i
SX/ieTZXVTF00I6BMMfE16UrVhUD/OIwmLwairnXZ1235sg4nw4NOk9ywjDQQSZA
YxPSH6oWCyMlMJV4xkGMze/55Q/u2zFjOLg4Vm9Z+9bS/b2e70qxFLH5ZFlRG3jn
DgknyCysv3IcDv5OYmEsQbFswPGEBYFcpOTf0RmLeQ9GpzwfAnQvQvscHqgqPHdI
Yicv49YP1RGeSrcWA4Rj
=7BDr
-----END PGP SIGNATURE-----


More information about the Wily-changes mailing list