[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#437708: marked as done (CVE-2007-3568: DoS vulnerability with crafted bmp)

Your message dated Tue, 14 Aug 2007 12:02:07 +0000
with message-id <E1IKv67-0007VL-Q4@ries.debian.org>
and subject line Bug#437708: fixed in imlib 1.9.15-3
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: imlib11
Version: 1.9.15-2
Severity: important
Tags: security

>From CVE-2007-3568:

"The _LoadBMP function in imlib 1.9.15 and earlier allows
context-dependent attackers to cause a denial of service (infinite
loop) via a BMP image with a Bits Per Page (BPP) value of 0."

See http://www.securiteam.com/unixfocus/5WP030UM0W.html for more information.

Please mention the CVE id in the changelog.

--- End Message ---
--- Begin Message ---
Source: imlib
Source-Version: 1.9.15-3

We believe that the bug you reported is fixed in the latest version of
imlib, which is due to be installed in the Debian FTP archive:

  to pool/main/i/imlib/gdk-imlib11-dev_1.9.15-3_i386.deb
  to pool/main/i/imlib/gdk-imlib11_1.9.15-3_i386.deb
  to pool/main/i/imlib/gdk-imlib1_1.9.15-3_all.deb
  to pool/main/i/imlib/imlib-base_1.9.15-3_all.deb
  to pool/main/i/imlib/imlib11-dev_1.9.15-3_i386.deb
  to pool/main/i/imlib/imlib11_1.9.15-3_i386.deb
  to pool/main/i/imlib/imlib_1.9.15-3.diff.gz
  to pool/main/i/imlib/imlib_1.9.15-3.dsc

A summary of the changes between this version and the previous one is

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 437708@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
Steffen Joeris <white@debian.org> (supplier of updated imlib package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)

Hash: SHA1

Format: 1.7
Date: Tue, 14 Aug 2007 11:13:36 +0000
Source: imlib
Binary: gdk-imlib1 gdk-imlib11-dev gdk-imlib11 imlib11 imlib-base imlib11-dev
Architecture: source i386 all
Version: 1.9.15-3
Distribution: unstable
Urgency: high
Maintainer: Debian QA Group <packages@qa.debian.org>
Changed-By: Steffen Joeris <white@debian.org>
 gdk-imlib1 - compatibility package for gdk-imlib11
 gdk-imlib11 - imaging library for use with gtk
 gdk-imlib11-dev - Header files needed for Gdk-Imlib development
 imlib-base - Common files needed by the Imlib/Gdk-Imlib packages
 imlib11    - Imlib is an imaging library for X and X11
 imlib11-dev - Imlib is an imaging library for X and X11
Closes: 437708
 imlib (1.9.15-3) unstable; urgency=high
   * QA upload by the testing security team
   * Include patch (bpp16-CVE-2007-3568.patch) to fix a DoS caused via a
     BMP image with a Bits Per Page (BPP) value of 0 (Closes: #437708)
     Fixes: CVE-2007-3568
     Thanks to Luciano Bello for forwarding the patch
 7f91f28fb927c9f3c9a48d788dbf1b33 815 graphics optional imlib_1.9.15-3.dsc
 e200d1eb403dc10463baf8b19a625e22 368320 graphics optional imlib_1.9.15-3.diff.gz
 cb7cba614df59517ddfecec73893047b 23686 graphics optional imlib-base_1.9.15-3_all.deb
 7a52cfcf07bba4ec362cc454b8c09199 16130 oldlibs optional gdk-imlib1_1.9.15-3_all.deb
 286c8fc7cd4bbea75b8dc3709739dbc7 85184 oldlibs optional imlib11_1.9.15-3_i386.deb
 4e12d0ca57be1d194ec48710e8edae4c 89242 libdevel optional imlib11-dev_1.9.15-3_i386.deb
 e8dfbb2ca97ba10611b07756d79a83e4 93434 oldlibs optional gdk-imlib11_1.9.15-3_i386.deb
 ad8c726846a5a9e09b7dfbf34dedd124 78418 oldlibs optional gdk-imlib11-dev_1.9.15-3_i386.deb

Version: GnuPG v1.4.6 (GNU/Linux)


--- End Message ---

Reply to: