[Technik] [SECURITY] [DSA 1256-1] New gtk+2.0 packages fix
denial of service
Noèl Köthe
noel at debian.org
Fri Feb 2 22:04:11 CET 2007
Am Mittwoch, den 31.01.2007, 23:09 +0100 schrieb Moritz Muehlenhoff:
> Debian Security Advisory DSA 1256-1 security at debian.org
> http://www.debian.org/security/ Moritz Muehlenhoff
> January 31st, 2007 http://www.debian.org/security/faq
>
> Package : gtk+2.0
> Vulnerability : programming error
> Problem-Type : local(remote)
> Debian-specific: no
> CVE ID : CVE-2007-0010
gtk+2.0 auf h01, h02, h03 und h04 aktualisiert.
> For the stable distribution (sarge) this problem has been fixed in
> version 2.6.4-3.2. This update lacks builds for the Motorola 680x0
> architecture, which had build problems. Packages will be released once
> this problem has been resolved.
changelog:
gtk+2.0 (2.6.4-3.2) stable-security; urgency=high
* Non-maintainer upload targetted at stable-security.
* SECURITY: New patch, 030_CVE-2007-0010_error-handling-in-pixbuf-loaders,
to fix error handling in pixbuf loaders; CVE-2007-0010;
RedHat #218755, #218932.
-- Loic Minier <lool at dooz.org> Thu, 25 Jan 2007 12:29:27 +0100
--
Noèl Köthe <noel debian.org>
Debian GNU/Linux, www.debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Dies ist ein digital signierter Nachrichtenteil
Url : /archiv/technik/attachments/20070202/ad0bd2bf/attachment.pgp
More information about the Technik
mailing list