Bug#550440: advi: CVE-2009-2295 arbitrary code execution

2009-10-11 Thread Mehdi Dogguy
Steffen Joeris a écrit : > Current problem is not to rebuild advi, but that camlimages' tiffread.c seems > to be vulnerable as well. This should be fixed first in a follow-up DSA > first. > Upstream doesn't seem reachable and the fedora guys don't seem to have time > either. Maybe you guys want

Bug#550440: advi: CVE-2009-2295 arbitrary code execution

2009-10-10 Thread Steffen Joeris
On Sun, 11 Oct 2009 07:38:01 am Mehdi Dogguy wrote: > Michael S Gilbert a écrit : > > Package: advi > > Version: 1.6.0-12 > > Severity: serious > > Tags: security > > > > Hi, > > > > The following CVE (Common Vulnerabilities & Exposures) id was > > published for camlimages. advi statically links t

Bug#550440: advi: CVE-2009-2295 arbitrary code execution

2009-10-10 Thread Mehdi Dogguy
Michael S Gilbert a écrit : > Package: advi > Version: 1.6.0-12 > Severity: serious > Tags: security > > Hi, > > The following CVE (Common Vulnerabilities & Exposures) id was > published for camlimages. advi statically links to camlimages, so any > issues in that package are also applicable to a

Bug#550440: advi: CVE-2009-2295 arbitrary code execution

2009-10-09 Thread Michael S Gilbert
Package: advi Version: 1.6.0-12 Severity: serious Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for camlimages. advi statically links to camlimages, so any issues in that package are also applicable to advi. There were already updates to camlimages f