Format: 1.8 Date: Sat, 21 Feb 2009 15:50:52 +1100 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: all i386 Version: 1.2.35-1 Distribution: karmic Urgency: high Maintainer: Ubuntu/i386 Build Daemon Changed-By: Anibal Monsalve Salazar Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 486415 516256 Changes: libpng (1.2.35-1) unstable; urgency=high . * New upstream release - http://secunia.com/advisories/33970/ Fix a vulnerability reported by Tavis Ormandy in which some arrays of pointers are not initialized prior to using "malloc" to define the pointers. Closes: #516256 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5907 The png_check_keyword function in pngwutil.c in libpng, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with keywords, related to an implicit cast of the '\0' character constant to a NULL pointer. * Don't build libpng3 when binary-indep target is not called. Closes: #486415 Checksums-Sha1: 1ea0ae3f6e8299f926b026a7a50e6df5059bfb99 928 libpng3_1.2.35-1_all.deb 12df99cde3430c5c72b4ce7c937bd035cde946c4 173204 libpng12-0_1.2.35-1_i386.deb fdf00f957f831e8775c32fffcffec564ac1e60d5 256450 libpng12-dev_1.2.35-1_i386.deb 263197f3aef927740f94761521d7d63d64c5233e 75644 libpng12-0-udeb_1.2.35-1_i386.udeb Checksums-Sha256: 3c973990a64ed0a06fafecac410c27bb5072fed2df02c0a54bd9154c2c72544d 928 libpng3_1.2.35-1_all.deb c6a4bf6401301261d3a9dcd9f37f635d1723457e98ad26f6d7ff51261c6dc2f4 173204 libpng12-0_1.2.35-1_i386.deb bad2dc49033b221e11cbb7de0f682853e7c6f48ea2cf6bb5ab6337b36078c814 256450 libpng12-dev_1.2.35-1_i386.deb 83d20c9e8646cd482461414ebd85f96a94fedc6f0b0cd013de7b08e6c562219c 75644 libpng12-0-udeb_1.2.35-1_i386.udeb Files: 4a99e24dadb1476e335700282872aa78 928 oldlibs optional libpng3_1.2.35-1_all.deb 7b46b01bb889a86f4636b5793b3111c8 173204 libs optional libpng12-0_1.2.35-1_i386.deb 3a530db3fdba71f5ddf44a71a3f34d79 256450 libdevel optional libpng12-dev_1.2.35-1_i386.deb 242de1da3d924e1958853f7ca9c4d7c7 75644 debian-installer extra libpng12-0-udeb_1.2.35-1_i386.udeb Package-Type: udeb