Your message dated Tue, 14 Aug 2007 12:02:07 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#437708: fixed in imlib 1.9.15-3
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--- Begin Message ---
Package: imlib11
Version: 1.9.15-2
Severity: important
Tags: security
>From CVE-2007-3568:
"The _LoadBMP function in imlib 1.9.15 and earlier allows
context-dependent attackers to cause a denial of service (infinite
loop) via a BMP image with a Bits Per Page (BPP) value of 0."
See http://www.securiteam.com/unixfocus/5WP030UM0W.html for more information.
Please mention the CVE id in the changelog.
--- End Message ---
--- Begin Message ---
Source: imlib
Source-Version: 1.9.15-3
We believe that the bug you reported is fixed in the latest version of
imlib, which is due to be installed in the Debian FTP archive:
gdk-imlib11-dev_1.9.15-3_i386.deb
to pool/main/i/imlib/gdk-imlib11-dev_1.9.15-3_i386.deb
gdk-imlib11_1.9.15-3_i386.deb
to pool/main/i/imlib/gdk-imlib11_1.9.15-3_i386.deb
gdk-imlib1_1.9.15-3_all.deb
to pool/main/i/imlib/gdk-imlib1_1.9.15-3_all.deb
imlib-base_1.9.15-3_all.deb
to pool/main/i/imlib/imlib-base_1.9.15-3_all.deb
imlib11-dev_1.9.15-3_i386.deb
to pool/main/i/imlib/imlib11-dev_1.9.15-3_i386.deb
imlib11_1.9.15-3_i386.deb
to pool/main/i/imlib/imlib11_1.9.15-3_i386.deb
imlib_1.9.15-3.diff.gz
to pool/main/i/imlib/imlib_1.9.15-3.diff.gz
imlib_1.9.15-3.dsc
to pool/main/i/imlib/imlib_1.9.15-3.dsc
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Steffen Joeris <[EMAIL PROTECTED]> (supplier of updated imlib package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Tue, 14 Aug 2007 11:13:36 +0000
Source: imlib
Binary: gdk-imlib1 gdk-imlib11-dev gdk-imlib11 imlib11 imlib-base imlib11-dev
Architecture: source i386 all
Version: 1.9.15-3
Distribution: unstable
Urgency: high
Maintainer: Debian QA Group <[EMAIL PROTECTED]>
Changed-By: Steffen Joeris <[EMAIL PROTECTED]>
Description:
gdk-imlib1 - compatibility package for gdk-imlib11
gdk-imlib11 - imaging library for use with gtk
gdk-imlib11-dev - Header files needed for Gdk-Imlib development
imlib-base - Common files needed by the Imlib/Gdk-Imlib packages
imlib11 - Imlib is an imaging library for X and X11
imlib11-dev - Imlib is an imaging library for X and X11
Closes: 437708
Changes:
imlib (1.9.15-3) unstable; urgency=high
.
* QA upload by the testing security team
* Include patch (bpp16-CVE-2007-3568.patch) to fix a DoS caused via a
BMP image with a Bits Per Page (BPP) value of 0 (Closes: #437708)
Fixes: CVE-2007-3568
Thanks to Luciano Bello for forwarding the patch
Files:
7f91f28fb927c9f3c9a48d788dbf1b33 815 graphics optional imlib_1.9.15-3.dsc
e200d1eb403dc10463baf8b19a625e22 368320 graphics optional
imlib_1.9.15-3.diff.gz
cb7cba614df59517ddfecec73893047b 23686 graphics optional
imlib-base_1.9.15-3_all.deb
7a52cfcf07bba4ec362cc454b8c09199 16130 oldlibs optional
gdk-imlib1_1.9.15-3_all.deb
286c8fc7cd4bbea75b8dc3709739dbc7 85184 oldlibs optional
imlib11_1.9.15-3_i386.deb
4e12d0ca57be1d194ec48710e8edae4c 89242 libdevel optional
imlib11-dev_1.9.15-3_i386.deb
e8dfbb2ca97ba10611b07756d79a83e4 93434 oldlibs optional
gdk-imlib11_1.9.15-3_i386.deb
ad8c726846a5a9e09b7dfbf34dedd124 78418 oldlibs optional
gdk-imlib11-dev_1.9.15-3_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGwZb262zWxYk/rQcRAjJlAJ9+ZoIkfCcazx5JZNCzlmlyJFEpZwCfVpy9
m6AgZ0XzW/xXThmkJ5FhI7s=
=PYep
-----END PGP SIGNATURE-----
--- End Message ---