-
Committer:
Bazaar Package Importer
-
Author(s):
Anibal Monsalve Salazar
-
Date:
2009-02-21 15:50:52 UTC
-
mfrom:
(1.1.6 upstream)
-
Revision ID:
james.westby@ubuntu.com-20090221155052-x0s21xidln6rlvzl
Tags: 1.2.35-1
* New upstream release
- http://secunia.com/advisories/33970/
Fix a vulnerability reported by Tavis Ormandy in which
some arrays of pointers are not initialized prior to using
"malloc" to define the pointers.
Closes: #516256
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5907
The png_check_keyword function in pngwutil.c in libpng, might
allow context-dependent attackers to set the value of an
arbitrary memory location to zero via vectors involving
creation of crafted PNG files with keywords, related to an
implicit cast of the '\0' character constant to a NULL pointer.
* Don't build libpng3 when binary-indep target is not called.
Closes: #486415