Sync lzo2 2.08-1 (main) from Debian unstable (main)

Bug #1393264 reported by Artur Rona
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
lzo2 (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please sync lzo2 2.08-1 (main) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
  * SECURITY UPDATE: denial of service or possible code execution via
    integer overflow
    - debian/patches/CVE-2014-4607.patch: check for overflow in
      minilzo/minilzo.c, src/lzo1_d.ch, src/lzo1b_d.ch, src/lzo1f_d.ch,
      src/lzo1x_d.ch, src/lzo2a_d.ch.
    - CVE-2014-4607
  * SECURITY UPDATE: denial of service or possible code execution via
    integer overflow
    - debian/patches/CVE-2014-4607.patch: check for overflow in
      minilzo/minilzo.c, src/lzo1_d.ch, src/lzo1b_d.ch, src/lzo1f_d.ch,
      src/lzo1x_d.ch, src/lzo2a_d.ch.
    - CVE-2014-4607
  * Build using dh-autoreconf.
  * Build using dh-autoreconf.

Debian supports autotools instead autoreconf.

Changelog entries since current vivid version 2.06-1.2ubuntu2:

lzo2 (2.08-1) unstable; urgency=low

  * New upstream release (closes: #752861) (CVE-2014-4607)
  * Update standards version
  * Add autotools-dev to build dependencies (closes: #750622)

 -- Peter Eisentraut <email address hidden> Mon, 14 Jul 2014 21:03:12 -0400

CVE References

Artur Rona (ari-tczew)
Changed in lzo2 (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Daniel Holbach (dholbach) wrote :

This bug was fixed in the package lzo2 - 2.08-1
Sponsored for Artur Rona (ari-tczew)

---------------
lzo2 (2.08-1) unstable; urgency=low

  * New upstream release (closes: #752861) (CVE-2014-4607)
  * Update standards version
  * Add autotools-dev to build dependencies (closes: #750622)

 -- Peter Eisentraut <email address hidden> Mon, 14 Jul 2014 21:03:12 -0400

Changed in lzo2 (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.