Bug#805113: CVE-2015-8126: buffer overflow

2015-11-17 Thread Salvatore Bonaccorso
Hey Nobohiro! On Wed, Nov 18, 2015 at 11:14:21AM +0900, Nobuhiro Iwamatsu wrote: > Hi, Salvatore. > > Thanks for your patch. > I will upload a new version that includes the changes to fix these bugs soon. Okay thanks, so no NMU needed. > And I will work for jessie and wheezy-security too. This

Bug#805113: CVE-2015-8126: buffer overflow

2015-11-17 Thread Nobuhiro Iwamatsu
Hi, Salvatore. Thanks for your patch. I will upload a new version that includes the changes to fix these bugs soon. And I will work for jessie and wheezy-security too. Best regards, Nobuhiro > Control: tags 805113 + patch > > Hi Anibal, > > Attached is debdiff I would propose for sid (jessie-

Bug#805113: CVE-2015-8126: buffer overflow

2015-11-16 Thread Sven Joachim
On 2015-11-14 12:54 -0800, Josh Triplett wrote: > Package: libpng12-0 > Version: 1.2.50-2+b2 > Severity: critical > Tags: security upstream > > Quoting https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8126 >> Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE >> functi

Bug#805113: CVE-2015-8126: buffer overflow

2015-11-14 Thread Josh Triplett
Package: libpng12-0 Version: 1.2.50-2+b2 Severity: critical Tags: security upstream Quoting https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8126 > Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE > functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.