Copied from
ubuntu precise in
Private PPA for Ubuntu Security Team
by Marc Deslauriers
Changelog
rpm (4.9.1.1-1ubuntu0.1) precise-security; urgency=low
* SECURITY UPDATE: denial of service and possible code execution via
crafted headers
- debian/patches/CVE-2011-3378.patch: properly validate values in
lib/header.c.
- CVE-2011-3378
* SECURITY UPDATE: denial of service and possible code execution via
invalid region tag
- debian/patches/CVE-2012-0060.patch: validate region tags in
lib/header.c, lib/package.c, lib/signature.c.
- CVE-2012-0060
* SECURITY UPDATE: denial of service and possible code execution via
large region size
- debian/patches/CVE-2012-0061.patch: check length in lib/header.c.
- CVE-2012-0061
* SECURITY UPDATE: denial of service and possible code execution via
negative value in region offset
- debian/patches/CVE-2012-0815.patch: properly handle negative values
in lib/header.c, lib/package.c, lib/signature.c.
- CVE-2012-0815
-- Marc Deslauriers <email address hidden> Thu, 17 Jan 2013 11:57:17 -0500