• [SECURITY] [DSA 3537-1] imlib2 security update

    From Sebastien Delafond@1:229/2 to All on Thu Mar 31 12:50:01 2016
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3537-1 [email protected] https://www.debian.org/security/ Sebastien Delafond
    March 31, 2016 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : imlib2
    CVE ID : CVE-2014-9762 CVE-2014-9763 CVE-2014-9764

    Several vulnerabilities were discovered in imlib2, an image
    manipulation library.

    CVE-2014-9762

    A segmentation fault could occur when opening GIFs without a
    colormap.

    CVE-2014-9763

    Several divisions by zero, resulting in a program crash, could
    occur when handling PNM files.

    CVE-2014-9764

    A segmentation fault could occur when opening GIFs with feh.

    For the oldstable distribution (wheezy), these problems have been fixed
    in version 1.4.5-1+deb7u1.

    For the stable distribution (jessie), these problems have been fixed in
    version 1.4.6-2+deb8u1.

    For the testing (stretch) and unstable (sid) distributions, these
    problems have been fixed in version 1.4.7-1.

    We recommend that you upgrade your imlib2 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v2

    iQEcBAEBCgAGBQJW/O3RAAoJEBC+iYPz1Z1kQoQIALWtewcOStnq1qGQ3f4EpTAG iJGQ7KkbybKkFwV2iL5E+Jru//rg48O9FPzlzkybykMf2EHjuTrO3TIbYWGMQ/+F bg1mmy2CiBCU48dIcKlSzc4mUd/zNyLIYiWMr8wUesy2f0qVbyHP1RwMHBJVS66i JvquLHylHPOpb9ZqT9Ww7FG400lme2F1EyYzTdJ1H143dkfe+tAp337EXaQesYGh bf5x4GFAosueCzoGTJGVrkXM8CgZOsQpVt83VB5qfim/77NcfHABifq9LJmqJw2u rKTrG7ahgYrDFMG1KfGEhKfT6dIYDEhbxpHRmjKLFRwAozVJrKNwrXL0tMDmBX0=
    =+MvP
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)