please sync sdl-image1.2 (1.2.6-3) from unstable/main to main, ubuntu override ok

Bug #190484 reported by StefanPotyra
4
Affects Status Importance Assigned to Milestone
sdl-image1.2 (Ubuntu)
Fix Released
High
StefanPotyra

Bug Description

Hi,

please sync sdl-image1.2 (1.2.6-3) from unstable/main to main, ubuntu override ok.

Ubuntu changes:
* disable dlopen and link against shared library libjpeg62.so
-> got applied in unstable as well.

Changelog:
sdl-image1.2 (1.2.6-3) unstable; urgency=low

  * CVE-2008-0544: Fix heap based buffer overflow.
  * Force library to link libjpeg and libtif and not dlopen them during
    runtime.

 -- Michael Koch <email address hidden> Tue, 05 Feb 2008 23:10:31 +0100

Thanks,
      Stefan.

CVE References

Revision history for this message
StefanPotyra (sistpoty) wrote :

Due to CVE, high importance.

Changed in sdl-image1.2:
assignee: nobody → sistpoty
importance: Undecided → High
status: New → Confirmed
Revision history for this message
Sarah Kowalik (hobbsee-deactivatedaccount) wrote :

+1

Revision history for this message
Steve Langasek (vorlon) wrote : Synced

Package(s) synced.

Changed in sdl-image1.2:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.