Paketname
netpbm
Datum
2009-12-05
Advisory ID
MDVSA-2009:317
Betroffene Versionen
2008.0 i586 , 2008.0 x86_64

Problembeschreibung

Multiple security vulnerabilities has been identified and fixed
in netpbm:

Multiple integer overflows in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via a crafted
image file, related to integer multiplication for memory allocation
(CVE-2008-3520).

Buffer overflow in the jas_stream_printf function in
libjasper/base/jas_stream.c in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via
vectors related to the mif_hdr_put function and use of vsprintf
(CVE-2008-3522).

pamperspective in Netpbm before 10.35.48 does not properly calculate
a window height, which allows context-dependent attackers to cause a
denial of service (crash) via a crafted image file that triggers an
out-of-bounds read (CVE-2008-4799).

Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers

This update fixes this vulnerability.

Aktualisierte Pakete

2008.0 i586

 7b0e45d3f024f928bf5efef1523d2bdc  2008.0/i586/libnetpbm10-10.34-8.2mdv2008.0.i586.rpm
 1429258b5054e99c9bcf17627ad84ff5  2008.0/i586/libnetpbm-devel-10.34-8.2mdv2008.0.i586.rpm
 d8a371066d668d750e0d5013b11a5bc4  2008.0/i586/libnetpbm-static-devel-10.34-8.2mdv2008.0.i586.rpm
 a89f33b6a389d50260acd1fa998a5c6f  2008.0/i586/netpbm-10.34-8.2mdv2008.0.i586.rpm 
 5a12f1cb9aec58e40d4bddaa4f08495a  2008.0/SRPMS/netpbm-10.34-8.2mdv2008.0.src.rpm

2008.0 x86_64

 53601f6261a9135bcd1bc2fd02f1569d  2008.0/x86_64/lib64netpbm10-10.34-8.2mdv2008.0.x86_64.rpm
 b8c2205ef64eebf42ae191fcb806523a  2008.0/x86_64/lib64netpbm-devel-10.34-8.2mdv2008.0.x86_64.rpm
 db3819cfc6341148161d3ee6c0301067  2008.0/x86_64/lib64netpbm-static-devel-10.34-8.2mdv2008.0.x86_64.rpm
 6d85ae6f25d97c8defa9891d63721956  2008.0/x86_64/netpbm-10.34-8.2mdv2008.0.x86_64.rpm 
 5a12f1cb9aec58e40d4bddaa4f08495a  2008.0/SRPMS/netpbm-10.34-8.2mdv2008.0.src.rpm

Referenzen