Bug#692435: gegl: CVE-2012-4433

2012-11-22 Thread Matteo F. Vescovi
Hi Michael! On Thu, Nov 22, 2012 at 10:25 AM, Michael Gilbert wrote: > I've uploaded an nmu fixing this issue. Please see attached patch. Ahhh... thanks for taking care of this bug. Sorry for the eternal delay in my reply, but in this period I'm overwhelmed by real-life stuff ;-) I'll apply yo

Bug#692435: gegl: CVE-2012-4433 - Integer overflow, leading to heap-based buffer overflow by parsing PPM image headers

2012-11-06 Thread Luciano Bello
Package: gegl Severity: grave Tags: security Justification: user security hole Hi, please see : http://seclists.org/oss-sec/2012/q4/215 Can you confirm if any of the Debian packages are affected? Cheers, luciano -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subjec