Publishing details

Changelog

ghostscript (8.71.dfsg.1-0ubuntu5.7) lucid-security; urgency=medium

  * SECURITY UPDATE: denial of service via crafted ICC color profile
    - debian/patches/CVE-2014-8137.dpatch: prevent double-free in
      jasper/src/libjasper/base/jas_icc.c, remove assert in
      jasper/src/libjasper/jp2/jp2_dec.c.
    - CVE-2014-8137
  * SECURITY UPDATE: denial of service or code execution via invalid
    channel number
    - debian/patches/CVE-2014-8138.dpatch: validate channel number in
      jasper/src/libjasper/jp2/jp2_dec.c.
    - CVE-2014-8138
  * SECURITY UPDATE: denial of service or code execution via off-by-one
    - debian/patches/CVE-2014-8157.dpatch: fix off-by-one in
      jasper/src/libjasper/jpc/jpc_dec.c.
    - CVE-2014-8157
  * SECURITY UPDATE: denial of service or code execution via memory
    corruption
    - debian/patches/CVE-2014-8158.dpatch: remove HAVE_VLA to use more
      sensible buffer sizes in jasper/src/libjasper/jpc/jpc_qmfb.c.
    - CVE-2014-8158
 -- Marc Deslauriers <email address hidden>   Thu, 22 Jan 2015 13:09:28 -0500

Available diffs

Builds

Package files