[ubuntu/xenial-updates] dosfstools 3.0.28-2ubuntu0.1 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Tue May 31 16:28:14 UTC 2016


dosfstools (3.0.28-2ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: out of bounds read denial of service
    - debian/patches/date_oob_read.patch: prevent out of bounds array read
      in src/check.c.
    - No CVE number
  * SECURITY UPDATE: memory corruption via off-by-2 in FAT12
    - debian/patches/CVE-2015-8872.patch: fix FAT12 logic in src/fat.c.
    - CVE-2015-8872
  * SECURITY UPDATE: heap overflow via excessive FAT size specifications
    - debian/patches/CVE-2016-4804.patch: change size and perform checks in
      src/boot.c, src/fsck.fat.h.
    - CVE-2016-4804

Date: 2016-05-26 11:50:17.110016+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/dosfstools/3.0.28-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list