Format: 1.8 Date: Sat, 21 Feb 2009 15:50:52 +1100 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: ia64 Version: 1.2.35-1 Distribution: karmic Urgency: high Maintainer: Ubuntu/ia64 Build Daemon Changed-By: Anibal Monsalve Salazar Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 486415 516256 Changes: libpng (1.2.35-1) unstable; urgency=high . * New upstream release - http://secunia.com/advisories/33970/ Fix a vulnerability reported by Tavis Ormandy in which some arrays of pointers are not initialized prior to using "malloc" to define the pointers. Closes: #516256 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5907 The png_check_keyword function in pngwutil.c in libpng, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with keywords, related to an implicit cast of the '\0' character constant to a NULL pointer. * Don't build libpng3 when binary-indep target is not called. Closes: #486415 Checksums-Sha1: d636d809625821f7b2a8e7118d6e115f3376bbde 212466 libpng12-0_1.2.35-1_ia64.deb 4061b3e63ed5f6c7964ac6ef80310f30fa2062fb 313212 libpng12-dev_1.2.35-1_ia64.deb c213fe01ce8326b4ba8007399e6993dd8821f669 115336 libpng12-0-udeb_1.2.35-1_ia64.udeb Checksums-Sha256: b2f518e1deb012c5e4fee22807fe002a849276d77dbacc484f8d40042d08ac86 212466 libpng12-0_1.2.35-1_ia64.deb ceac1b2565bcde06273e174856c39566ba68dde4ba6c3e2ac12ed2e7256c7e94 313212 libpng12-dev_1.2.35-1_ia64.deb e29bfa47a9a9300e48adcf7a8da6ef335c6a93ef5026daa127810bbd71ef28c5 115336 libpng12-0-udeb_1.2.35-1_ia64.udeb Files: ca91d0a33f56970fe61191c85a027559 212466 libs optional libpng12-0_1.2.35-1_ia64.deb a6fe2b1dbf0e80b93aed900d919f5eff 313212 libdevel optional libpng12-dev_1.2.35-1_ia64.deb 8218f16c1eded93320d24cfde0ce0368 115336 debian-installer extra libpng12-0-udeb_1.2.35-1_ia64.udeb Package-Type: udeb