Bug#445303: [Pkg-tcltk-devel] Bug#445303: CVE-2007-5137 arbitrary code execution via multi-frame interlaced GIF

2007-10-04 Thread Nico Golde
Hi, * Sergei Golovan <[EMAIL PROTECTED]> [2007-10-04 21:49]: > On 10/4/07, Nico Golde <[EMAIL PROTECTED]> wrote: > > the following CVE (Common Vulnerabilities & Exposures) id was > > published for tk8.3. > > I'll upload a fixed version shortly. Should I also prepare a package > for uploading to st

Bug#445303: [Pkg-tcltk-devel] Bug#445303: CVE-2007-5137 arbitrary code execution via multi-frame interlaced GIF

2007-10-04 Thread Sergei Golovan
On 10/4/07, Nico Golde <[EMAIL PROTECTED]> wrote: > > Hi, > the following CVE (Common Vulnerabilities & Exposures) id was > published for tk8.3. I'll upload a fixed version shortly. Should I also prepare a package for uploading to stable-security? -- Sergei Golovan -- To UNSUBSCRIBE, email t

Bug#445303: CVE-2007-5137 arbitrary code execution via multi-frame interlaced GIF

2007-10-04 Thread Nico Golde
Package: tk8.3 Version: 8.3.5-4 Severity: grave Tags: security patch Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for tk8.3. CVE-2007-5137[0]: | Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl | (Tcl/Tk) before 8.4.16 allows remote attackers t