[Gelistirici] 2011/devel/tex/tool/xfig - Fix stack-based buffer overflow by processing cert...

H. İbrahim Güngör ibrahim at pardus.org.tr
21 Ara 2010 Sal 12:59:28 EET


On Mon, 20 Dec 2010 23:24:26 +0200 (EET)
Fatih Arslan <paketler-commits at pardus.org.tr> wrote:

> Author: fatih.arslan
> Date: Mon Dec 20 23:24:24 2010
> New Revision: 107588
> 
> Added:
>    2011/devel/tex/tool/xfig/files/fix_buffer_overflow_cve_4262.diff
> Modified:
>    2011/devel/tex/tool/xfig/pspec.xml
> Log:
> Fix stack-based buffer overflow by processing certain FIG images
> (CVE-2010-4262)
> 
> 
> ---
>  files/fix_buffer_overflow_cve_4262.diff |   22 ++++++++++++++++++++++
>  pspec.xml                               |    8 ++++++++
>  2 files changed, 30 insertions(+)
> 
> Modified: 2011/devel/tex/tool/xfig/pspec.xml
> =================================================================
> --- 2011/devel/tex/tool/xfig/pspec.xml	(original)
> +++ 2011/devel/tex/tool/xfig/pspec.xml	Mon Dec 20 23:24:24 2010
> @@ -29,6 +29,7 @@
>              <Patch>xfig-paths.patch</Patch>
>              <Patch>xfig.main.c-firefox-kpdf.patch</Patch>
>              <Patch>xfig-3.2.5a-default-apps.patch</Patch>
> +            <Patch level="0">fix_buffer_overflow_cve_4262.diff</Patch>
>          </Patches>
>      </Source>
>  
> @@ -68,6 +69,13 @@
>     </Package>
>  
>     <History>
> +        <Update release="12">
> +            <Date>2010-12-20</Date>
> +            <Version>3.2.5b</Version>
> +            <Comment>Fix stack-based buffer overflow by processing certain
> FIG images (CVE-2010-4262)</Comment>
> +            <Name>Fatih Arslan</Name>
> +            <Email>farslan at pardus.org.tr</Email>
> +        </Update>

security etiketini koymayı unutmuşsun. Aynı açık, Kurumsal2 ve 2009'daki xfig
paketlerinde de yok mu?

Kolay gelsin.

-- 
H. İbrahim Güngör <ibrahim at pardus.org.tr>



Gelistirici mesaj listesiyle ilgili daha fazla bilgi