Bug#582116: texlive-bin: CVE-2010-0829 multiple array index errors

2010-05-20 Thread Michael Gilbert
> grep'ing for jpeg on texlive-bin build log [1], shows that system > libjpeg is installed during build, and also does not show that a libjpeg > is being built or even linked against ! upstream probably includes that as a dependency of libgd2, which is why its there. thanks for clearing this up

Bug#582116: texlive-bin: CVE-2010-0829 multiple array index errors

2010-05-19 Thread أحمد المحمودي
On Wed, May 19, 2010 at 10:25:14PM +0900, Norbert Preining wrote: > > libjpeg > > not sure. ---end quoted text--- grep'ing for jpeg on texlive-bin build log [1], shows that system libjpeg is installed during build, and also does not show that a libjpeg is being built or even linked against ! [

Bug#582116: texlive-bin: CVE-2010-0829 multiple array index errors

2010-05-19 Thread Norbert Preining
Hi Michael, On Di, 18 Mai 2010, Michael Gilbert wrote: > this is actually my fault. i had recently checked the texlive-bin > package for the existence embedded code copies, but didn't do a > complete job to determine if those embeds were actually. that's a lot Well, dlocate dvipng is not that h

Bug#582116: texlive-bin: CVE-2010-0829 multiple array index errors

2010-05-18 Thread Michael Gilbert
> And could you *PLEASE* verify *before* submitting a grave bug that this > actually applies to the pacakge? this is actually my fault. i had recently checked the texlive-bin package for the existence embedded code copies, but didn't do a complete job to determine if t

Bug#582116: texlive-bin: CVE-2010-0829 multiple array index errors

2010-05-18 Thread Sebastien Delafond
Source: texlive-bin Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for texlive-bin: CVE-2010-0829[0]: | Multiple array index errors in set.c in dvipng 1.11 and 1.12, and | teTeX, allow remote attackers to cause a denial of service | (ap