[Sync request] Sync graphicsmagick (1.1.7-14) from Debian unstable (main)

Bug #103843 reported by Michael Bienia
4
Affects Status Importance Assigned to Milestone
graphicsmagick (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: graphicsmagick

Please sync graphicsmagick (1.1.7-14) from Debian unstable (main).

The Ubuntu package has no changes.

The package builds cleanly in a feisty pbuilder.

Thanks.

Changelog:

graphicsmagick (1.1.7-14) unstable; urgency=high

  * magick/image.c: Fix heap overflow in GrayscalePseudoClassImage() on
    64bit architectures. (Turned up by Sami Liedes' segv2.viff test case.)
    Closes: #418052, #416096
  * magick/utility.h: Avoid double free() when calling MagickReallocMemory()
    with zero size argument. (Triggered by Sami Liedes' segv2.viff test case.)
    Closes: #418053
  * coders/tiff.c: Fix segfault with certain TIFF images on amd64 due to
    va_list reusal in bogus duplicate vsprintf() call. Thanks to Kurt
    Roeckx for the fix. Closes: #415467
  * coders/viff.c: Add sanity check to prevent heap overflow reading corrupt
    viff images. (Triggered by Sami Liedes' segv.viff test case.)
    Closes: #418054
  * coders/xwd.c: Fix integer overflow in XWD coders. (Triggered by Sami
    Liedes' broken.xwd test case.) Original patch thanks to Larry
    Doolittle. Closes: #417862

 -- Daniel Kobras <email address hidden> Fri, 6 Apr 2007 17:50:35 +0200

Michael Bienia (geser)
Changed in graphicsmagick:
status: Unconfirmed → Confirmed
Revision history for this message
Martin Pitt (pitti) wrote :

[Updating] graphicsmagick (1.1.7-13 [Ubuntu] < 1.1.7-14 [Debian])
 * Trying to add graphicsmagick...
  - <graphicsmagick_1.1.7.orig.tar.gz: already in distro - downloading from librarian>
  - <graphicsmagick_1.1.7-14.diff.gz: downloading from http://ftp.debian.org/debian/>
  - <graphicsmagick_1.1.7-14.dsc: downloading from http://ftp.debian.org/debian/>

Changed in graphicsmagick:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.