• [SECURITY] [DSA 3215-1] libgd2 security update

    From Alessandro Ghedini@1:229/2 to All on Mon Apr 6 20:40:02 2015
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3215-1 [email protected] http://www.debian.org/security/ Alessandro Ghedini
    April 06, 2015 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : libgd2
    CVE ID : CVE-2014-2497 CVE-2014-9709
    Debian Bug : 744719

    Multiple vulnerabilities were discovered in libgd2, a graphics library:

    CVE-2014-2497

    The gdImageCreateFromXpm() function would try to dereference a NULL
    pointer when reading an XPM file with a special color table. This
    could allow remote attackers to cause a denial of service (crash) via
    crafted XPM files.

    CVE-2014-9709

    Importing an invalid GIF file using the gdImageCreateFromGif() function
    would cause a read buffer overflow that could allow remote attackers to
    cause a denial of service (crash) via crafted GIF files.

    For the stable distribution (wheezy), these problems have been fixed in
    version 2.0.36~rc1~dfsg-6.1+deb7u1.

    For the upcoming stable distribution (jessie), these problems have been
    fixed in version 2.1.0-5.

    For the unstable distribution (sid), these problems have been fixed in
    version 2.1.0-5.

    We recommend that you upgrade your libgd2 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCgAGBQJVItElAAoJEAVMuPMTQ89EHlYQAJZNN6UmWnKm3aXtFofBAAuY nKf/oh8wHtyfuGNtTd9/u9II3FSP6Nv9n8eLiwJJeNluVEfXas28P4+8MNXsr/Hz 5VJPclhOUyU+r1DwtmIuFG1WlBhp8wYd/42OvRFm8N6AI0Qm8uibfMcszSmUdf/d Hyu8tpPpIY6dC++4nAh5yoYwatnk04B5us9CBoyEXTNEpc9JUL2ZtJGn0/HGgT6t ly3/Da6c6GZQm+7XOgLnZVvKLZ53KafTPWB3VimEfcCS2YFoaR8GyP8AM1G11QRQ 9xPMNUCYECMrLs2HRBFQAP1/vBi/TOgwTe7Xaf2xZXPWQKpsHFi6iX/uLQLqJ5T/ 9nN95AiKIiapHjscEY6qkJFOewCkSJ5FEWXsKOhr++uyY5iV+6ouia+UK/cPmZvY fGd7pWym2KbffeyeUD3ZDhTkq0cKAoLp/Dvg6K+ld5THQD0sjtjHDY+u7IgzcwiS fp+Ge8zr7hkSFUWs3iD3Tmclbqm81OafD8THdmA3bGwHfdbodlTOrnxhuHnP3xut HUzCaosz+o54TI0Ut9317qk2ORki4WJZJM16JMPSRc+54iSR3bSi0A1M85iD3zvh 9OgAQjNFkjkmbyy1x3Ug5cK/A6go9II0+RpzCHzN3wvBDaC4ncylIAXeZqbLnCHq 44liL++Xwgg4YFq1KExk
    =HyfC
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)