Package: libungif4g
Version: 4.1.3-2
Severity: critical
Tags: security patch

Hi!

Chris Evans discovered several buffer overflows (CVE-2005-3350) and a
NULL dereference (CVE-2005-2974), which were fixed upstream in 4.1.4.

Here is the Ubuntu patch which only contains the security relevant
bits:

http://patches.ubuntu.com/patches/libungif4.CVE-2005-2974_3350.diff

Thanks,

Martin

-- 
Martin Pitt        http://www.piware.de
Ubuntu Developer   http://www.ubuntu.com
Debian Developer   http://www.debian.org

Attachment: signature.asc
Description: Digital signature

Reply via email to