Please sync libdumb (universe) from unstable

Bug #53987 reported by Martin Pitt
4
Affects Status Importance Assigned to Milestone
libdumb (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 affects distros/ubuntu/libdumb
 status confirmed
 subscribe ubuntu-archive

Please sync libdumb (universe) from Debian unstable.

Changelog since current edgy version 1:0.9.3-4:

libdumb (1:0.9.3-5) unstable; urgency=critical

  * Set urgency=critical because of security fix.

  * debian/patches/100_CVE-2006-3668.diff:
    + Fix for CVE-2006-3668 "Heap-based buffer overflow in the it_read_envelope
      function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and
      earlier, and current CVS as of 20060716, allows user-complicit attackers
      to execute arbitrary code via a ".it" (Impulse Tracker) file with an
      enveloper with a large number of nodes." (Closes: #379064).

  * debian/control:
    + Set policy to 3.7.2.

 -- Sam Hocevar (Debian packages) <email address hidden> Fri, 21 Jul 2006 11:07:45 +0200

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iD8DBQFExa9eDecnbV4Fd/IRAq2OAJ4vbpzBb2Hus09wDoBBIJSZ0AsMPwCfWwDJ
V4JYVIJ/djSPXfCvDpkaESA=
=4+pq
-----END PGP SIGNATURE-----

Revision history for this message
Scott James Remnant (Canonical) (canonical-scott) wrote :

[Updating] libdumb (1:0.9.3-4 [Ubuntu] < 1:0.9.3-5 [Debian])
 * Trying to add libdumb...
  - <libdumb_0.9.3.orig.tar.gz: already in distro - downloading from librarian>
  - <libdumb_0.9.3-5.diff.gz: downloading from http://ftp.debian.org/debian/>
  - <libdumb_0.9.3-5.dsc: downloading from http://ftp.debian.org/debian/>
I: libdumb [universe] -> libaldmb1-dev_1:0.9.3-4 [universe].
I: libdumb [universe] -> libdumb1-dev_1:0.9.3-4 [universe].
I: libdumb [universe] -> libaldmb1_1:0.9.3-4 [universe].
I: libdumb [universe] -> libdumb1_1:0.9.3-4 [universe].

Changed in libdumb:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.