• [SECURITY] [DSA 2754-1] exactimage security update

    From Raphael Geissert@1:229/2 to All on Wed Sep 11 00:40:01 2013
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2754-1 [email protected] http://www.debian.org/security/ Raphael Geissert September 10, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : exactimage
    Vulnerability : denial of service
    Problem type : local (remote)
    Debian-specific: no
    CVE ID : CVE-2013-1441

    It was discovered that exactimage, a fast image processing library,
    does not correctly handle error conditions of the embedded copy of
    dcraw. This could result in a crash or other behaviour in an
    application using the library due to an uninitialized variable being
    passed to longjmp.

    This is a different issue than CVE-2013-1438/DSA-2748-1.

    For the oldstable distribution (squeeze), this problem has been fixed in version 0.8.1-3+deb6u3.

    For the stable distribution (wheezy), this problem has been fixed in
    version 0.8.5-5+deb7u3.

    For the testing distribution (jessie) and the unstable distribution
    (sid), this problem has been fixed in version 0.8.9-2.

    We recommend that you upgrade your exactimage packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.12 (GNU/Linux)

    iEYEARECAAYFAlIvnOUACgkQYy49rUbZzlqXUACgh0rpuhTnKiiYhI7DOsKU0IeD rF4AnA2bCBKuZcY4TGhCCELQ8uf9N2qZ
    =a/07
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)