Format: 1.8 Date: Sat, 21 Feb 2009 15:50:52 +1100 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: lpia Version: 1.2.35-1 Distribution: karmic Urgency: high Maintainer: Ubuntu/lpia Build Daemon Changed-By: Anibal Monsalve Salazar Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 486415 516256 Changes: libpng (1.2.35-1) unstable; urgency=high . * New upstream release - http://secunia.com/advisories/33970/ Fix a vulnerability reported by Tavis Ormandy in which some arrays of pointers are not initialized prior to using "malloc" to define the pointers. Closes: #516256 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5907 The png_check_keyword function in pngwutil.c in libpng, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with keywords, related to an implicit cast of the '\0' character constant to a NULL pointer. * Don't build libpng3 when binary-indep target is not called. Closes: #486415 Checksums-Sha1: 6f914783bd2588bd13d5354536e2e880d8c79733 163412 libpng12-0_1.2.35-1_lpia.deb 37fab9c132da618c580821d0668ffcae4a47ee8f 246694 libpng12-dev_1.2.35-1_lpia.deb e28c2bf4bd944fe18c0c97230c9c11e3d7e6b4b1 66244 libpng12-0-udeb_1.2.35-1_lpia.udeb Checksums-Sha256: 8c93063a03f65c5f510c657f2d578168c1d90daef29608829829e0207a9cddcf 163412 libpng12-0_1.2.35-1_lpia.deb 832fc3befcfc8495e807c7a675a4e64facae80bee9c2f6df374927a6830ee9fc 246694 libpng12-dev_1.2.35-1_lpia.deb e6609f8fec45024f8d9e2ec06e0191b297d81060f47dd7077c62c7ba0ca44ca3 66244 libpng12-0-udeb_1.2.35-1_lpia.udeb Files: 69e3a48b20f8335488685a186305d656 163412 libs optional libpng12-0_1.2.35-1_lpia.deb df6d1facebd203ed38614dda9f073577 246694 libdevel optional libpng12-dev_1.2.35-1_lpia.deb daae34f824bd79413c24bd43b74c9e15 66244 debian-installer extra libpng12-0-udeb_1.2.35-1_lpia.udeb Package-Type: udeb