Please sync optipng 0.6.2.1-1 from Debian unstable

Bug #297440 reported by Nelson A. de Oliveira
256
Affects Status Importance Assigned to Milestone
optipng (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: optipng

Hi!

I have upload a new version of optipng to Debian unstable, fixing a security vulnerability (Secunia Advisory SA32651).
Changes from 0.6.1-2 (jaunty) are small (see http://lists.debian.org/debian-release/2008/11/msg00413.html).
Note that version 0.6-1 (from intrepid) is also vulnerable.

Thank you!

 optipng (0.6.2.1-1) unstable; urgency=high

   * New upstream release:
     - Fix an array overflow vulnerability.

 -- Nelson A. de Oliveira <email address hidden> Thu, 26 Feb 2009 15:48:25 -0300

optipng (0.6.2-1) experimental; urgency=low

   * New upstream release;
   * Fix broken link /usr/share/doc/optipng/changelog.gz;
   * OptiPNG now produces a less verbose output (Closes: #457772).

 -- Nelson A. de Oliveira <email address hidden> Tue, 11 Nov 2008 13:26:52 -0200

CVE References

Kees Cook (kees)
Changed in optipng (Ubuntu):
status: New → Confirmed
Revision history for this message
Daniel Holbach (dholbach) wrote :

Sponsor ACK.

description: updated
summary: - Sync optipng from Debian unstable
+ Please sync optipng 0.6.2.1-1 from Debian unstable
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

[Updating] optipng (0.6.1.1-1 [Ubuntu] < 0.6.2.1-1 [Debian])
 * Trying to add optipng...
  - <optipng_0.6.2.1-1.dsc: downloading from http://ftp.debian.org/debian/>
  - <optipng_0.6.2.1-1.diff.gz: downloading from http://ftp.debian.org/debian/>
  - <optipng_0.6.2.1.orig.tar.gz: downloading from http://ftp.debian.org/debian/>
I: optipng [universe] -> optipng_0.6.1.1-1 [universe].

Changed in optipng (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.