[ubuntu/xenial-security] libraw 0.17.1-1ubuntu0.2 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Tue Apr 3 16:43:32 UTC 2018
libraw (0.17.1-1ubuntu0.2) xenial-security; urgency=medium
* SECURITY UPDATE: buffer overflow in panasonic_load_raw
- debian/patches/CVE-2017-16909.patch: add more bounds checking to
dcraw/dcraw.c, internal/dcraw_common.cpp, libraw/libraw_const.h.
- CVE-2017-16909
* SECURITY UPDATE: invalid read in xtrans_interpolate
- debian/patches/CVE-2017-16910.patch: add checks and proper
initialization to dcraw/dcraw.c, internal/dcraw_common.cpp.
- CVE-2017-16910
* SECURITY UPDATE: multiple security issues
- debian/patches/CVE-2018-580x.patch: add checks to dcraw/dcraw.c,
internal/dcraw_common.cpp, src/libraw_cxx.cpp.
- CVE-2018-5800
- CVE-2018-5801
- CVE-2018-5802
* SECURITY UPDATE: image size and alloc issues
- debian/patches/security_0.18.8_1.patch: add more checks to
dcraw/dcraw.c, internal/dcraw_common.cpp, libraw/libraw_const.h,
src/libraw_cxx.cpp.
- No CVE number
* SECURITY UPDATE: Secunia #81000 security issues
- debian/patches/security_0.18.8_2.patch: add more checks to
dcraw/dcraw.c, internal/dcraw_common.cpp.
- No CVE number
Date: 2018-03-30 15:05:18.426879+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libraw/0.17.1-1ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list