MDVSA-2009:317
- Package name
- netpbm
- Date
- 2009-12-05
- Advisory ID
- MDVSA-2009:317
- Affected versions
- 2008.0 i586 , 2008.0 x86_64
Problem description
Multiple security vulnerabilities has been identified and fixed
in netpbm:
Multiple integer overflows in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via a crafted
image file, related to integer multiplication for memory allocation
(CVE-2008-3520).
Buffer overflow in the jas_stream_printf function in
libjasper/base/jas_stream.c in JasPer 1.900.1 might allow
context-dependent attackers to have an unknown impact via
vectors related to the mif_hdr_put function and use of vsprintf
(CVE-2008-3522).
pamperspective in Netpbm before 10.35.48 does not properly calculate
a window height, which allows context-dependent attackers to cause a
denial of service (crash) via a crafted image file that triggers an
out-of-bounds read (CVE-2008-4799).
Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers
This update fixes this vulnerability.
Updated packages
2008.0 i586
7b0e45d3f024f928bf5efef1523d2bdc 2008.0/i586/libnetpbm10-10.34-8.2mdv2008.0.i586.rpm 1429258b5054e99c9bcf17627ad84ff5 2008.0/i586/libnetpbm-devel-10.34-8.2mdv2008.0.i586.rpm d8a371066d668d750e0d5013b11a5bc4 2008.0/i586/libnetpbm-static-devel-10.34-8.2mdv2008.0.i586.rpm a89f33b6a389d50260acd1fa998a5c6f 2008.0/i586/netpbm-10.34-8.2mdv2008.0.i586.rpm 5a12f1cb9aec58e40d4bddaa4f08495a 2008.0/SRPMS/netpbm-10.34-8.2mdv2008.0.src.rpm
2008.0 x86_64
53601f6261a9135bcd1bc2fd02f1569d 2008.0/x86_64/lib64netpbm10-10.34-8.2mdv2008.0.x86_64.rpm b8c2205ef64eebf42ae191fcb806523a 2008.0/x86_64/lib64netpbm-devel-10.34-8.2mdv2008.0.x86_64.rpm db3819cfc6341148161d3ee6c0301067 2008.0/x86_64/lib64netpbm-static-devel-10.34-8.2mdv2008.0.x86_64.rpm 6d85ae6f25d97c8defa9891d63721956 2008.0/x86_64/netpbm-10.34-8.2mdv2008.0.x86_64.rpm 5a12f1cb9aec58e40d4bddaa4f08495a 2008.0/SRPMS/netpbm-10.34-8.2mdv2008.0.src.rpm
