Your message dated Tue, 15 Sep 2015 17:19:25 +0000 with message-id <[email protected]> and subject line Bug#796270: fixed in gdk-pixbuf 2.31.7-1 has caused the Debian Bug report #796270, regarding Please disable jasper support to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 796270: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796270 Debian Bug Tracking System Contact [email protected] with problems
--- Begin Message ---Source: gdk-pixbuf Severity: important Hi, please disable jasper support in gdk-pixbuf. It's an abandoned code base with frequent security issues and JPEG2000 is an exotic fringe format unused in practice. We can keep it in the archive for scientific software etc, but let's not expose via gdk-pixbuf to exposed applications like Iceweasel. Cheers, Moritz
--- End Message ---
--- Begin Message ---Source: gdk-pixbuf Source-Version: 2.31.7-1 We believe that the bug you reported is fixed in the latest version of gdk-pixbuf, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Iain Lane <[email protected]> (supplier of updated gdk-pixbuf package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Sep 2015 16:24:31 +0100 Source: gdk-pixbuf Binary: libgdk-pixbuf2.0-0 libgdk-pixbuf2.0-0-dbg libgdk-pixbuf2.0-common libgdk-pixbuf2.0-dev libgdk-pixbuf2.0-doc libgdk-pixbuf2.0-0-udeb gir1.2-gdkpixbuf-2.0 Architecture: source amd64 all Version: 2.31.7-1 Distribution: unstable Urgency: medium Maintainer: Debian GNOME Maintainers <[email protected]> Changed-By: Iain Lane <[email protected]> Description: gir1.2-gdkpixbuf-2.0 - GDK Pixbuf library - GObject-Introspection libgdk-pixbuf2.0-0 - GDK Pixbuf library libgdk-pixbuf2.0-0-dbg - GDK Pixbuf library - debug symbols libgdk-pixbuf2.0-0-udeb - GDK Pixbuf library - minimal runtime (udeb) libgdk-pixbuf2.0-common - GDK Pixbuf library - data files libgdk-pixbuf2.0-dev - GDK Pixbuf library (development files) libgdk-pixbuf2.0-doc - GDK Pixbuf library (documentation) Closes: 753569 796270 Changes: gdk-pixbuf (2.31.7-1) unstable; urgency=medium . [ Michael Biebl ] * New upstream release. - Fixes CVE-2015-4491 (crash with malicious BMP files) * Disable jasper support. It's an abandoned code base with frequent security issues and JPEG2000 is an exotic fringe format unused in practice. Closes: #796270 . [ Iain Lane ] * New upstream release 2.31.7 - Fix several integer overflows (Closes: #753569) - Fix build failure with --disable-modules - Port animations to GTask Checksums-Sha1: 05617ee47a19cedcf93a14bdaa3d8ffc5129cdae 2846 gdk-pixbuf_2.31.7-1.dsc bbf3df35213d0ce6ec7b70efc5fd0934cdcf172e 2430852 gdk-pixbuf_2.31.7.orig.tar.xz c8bf856334a80731a87279c7903f1e80c17fe9b4 11856 gdk-pixbuf_2.31.7-1.debian.tar.xz 3927a6a8327005b8290fa77dbe12fac44a6a2c13 18386 gir1.2-gdkpixbuf-2.0_2.31.7-1_amd64.deb 3c2e27826395f492dc8ea68b0d2bad9ccfbe47df 443148 libgdk-pixbuf2.0-0-dbg_2.31.7-1_amd64.deb 729c77367d22670603b28d3e73daf6e9540de2f5 383478 libgdk-pixbuf2.0-0-udeb_2.31.7-1_amd64.udeb f21accb260bfa141c5c4e1095dfbd14aa8661680 168212 libgdk-pixbuf2.0-0_2.31.7-1_amd64.deb 4143ab3b023d1d09edf0c98dc9a95dada5e847af 309686 libgdk-pixbuf2.0-common_2.31.7-1_all.deb 7549d2d4c9f7277edfbee6695e82bb904dfcc346 54776 libgdk-pixbuf2.0-dev_2.31.7-1_amd64.deb 7b0bc72d6c280268c9de9a69a15c6578ab196bab 177520 libgdk-pixbuf2.0-doc_2.31.7-1_all.deb Checksums-Sha256: 359dd6057f6f6718a8f3720e07eab0a8801c49ebff9cc04d853dcae255547411 2846 gdk-pixbuf_2.31.7-1.dsc 4736e009168857ce8bb19291f0887c1dc6551cbc3c46d5ffcd034e133e4fd610 2430852 gdk-pixbuf_2.31.7.orig.tar.xz fcc12a5f5cf807f3a57368dbb8cddae2f9228fecb9bb53afbda378f0a03fac8e 11856 gdk-pixbuf_2.31.7-1.debian.tar.xz b27d55ae8a2f1e33b045c21f5fab3545952268e824be2f7a0d4a32b628cd9cb4 18386 gir1.2-gdkpixbuf-2.0_2.31.7-1_amd64.deb 58dffbad0848f2a7149de9d7a9ddf33a35a820ef772e9ef4c2292c01010534d9 443148 libgdk-pixbuf2.0-0-dbg_2.31.7-1_amd64.deb ab66a397a9b19c2b100e45d88aa9902ce75ade0c0d86c46bffb00539a439f21c 383478 libgdk-pixbuf2.0-0-udeb_2.31.7-1_amd64.udeb 8a69619a7ff979b67800bdace9d4c4580407dbe6f2f4a4d87baa636b12c05827 168212 libgdk-pixbuf2.0-0_2.31.7-1_amd64.deb 84c41b21e8d23dd84f199e4cb6861ed52e5c6ebf5153c5564574ac22696bbe0c 309686 libgdk-pixbuf2.0-common_2.31.7-1_all.deb f3aff7b6bc5050e2b6f038f42e8bc3b82bc791602df762e4a2a7d2125c28ecce 54776 libgdk-pixbuf2.0-dev_2.31.7-1_amd64.deb 77fe05b48fd7385339662bdd6b588a2b6efa3c0155d8c2c19c2a29f444855e58 177520 libgdk-pixbuf2.0-doc_2.31.7-1_all.deb Files: 13299f6dc2d4c6b69452ab7d67ad2bac 2846 libs optional gdk-pixbuf_2.31.7-1.dsc 8a42218ed76a75e38dc737c0c5d30190 2430852 libs optional gdk-pixbuf_2.31.7.orig.tar.xz 990959a5c7b2b869b9787f8a90a5eaab 11856 libs optional gdk-pixbuf_2.31.7-1.debian.tar.xz 91688b20415bbdd77b09ccc3b2146988 18386 introspection optional gir1.2-gdkpixbuf-2.0_2.31.7-1_amd64.deb 73f8f7fe097f46575eb5509be7a5a5d8 443148 debug extra libgdk-pixbuf2.0-0-dbg_2.31.7-1_amd64.deb e79684e0d01955a9ddf071112a9efd52 383478 debian-installer extra libgdk-pixbuf2.0-0-udeb_2.31.7-1_amd64.udeb 1c9b4ac4c40f20d84accfd4c669d81ab 168212 libs optional libgdk-pixbuf2.0-0_2.31.7-1_amd64.deb 965bc6c4d82ea42f7d70b37de3f1d66a 309686 libs optional libgdk-pixbuf2.0-common_2.31.7-1_all.deb e1d080ecef709c5622ea1026ea9e7f95 54776 libdevel optional libgdk-pixbuf2.0-dev_2.31.7-1_amd64.deb dfa68845c8aa617fd2f1f875c2d5e3e8 177520 doc optional libgdk-pixbuf2.0-doc_2.31.7-1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJV+EmHAAoJEONS1cUcUEHULkwP/jAlhYfVE6ldQ+z5sMfuJjUT 8mTZzRONMrX4ldM2ETjL/fYYlISzpuGF8IgJRqKIcu1UtiqPmqgROsH40XJxnHv8 ZLB7fLzmWiOSfThSqoCKP3ltdKPBEMy6KAnS0If+nZxf/YOKKjJgIhnvUuhKhn95 ZEgerXtXQsZS3xwfmzlSJHf8gMqCceX3a3cBPS9Ugxv1fndemubNCziaHdKog5Gu 3R98f2XaKWCMB8TvjkBRbiu4mEWA9P2DVQShE87CLgaFFa9drqYRy4oL75FleF06 1k631iX8BOG7JhW9btIVXDdN2kYnHaYkhUU1OyylxvLZYtbKICom0nZMBdsB7KUp IU1mkO254H0EEuPF0SnFEbRkHsLjnY0XQ61zsvrvU/iBiMfKOGZV0sYUIaHkB+Ar N3IPE3L9APVh93JmEjJBSU9YjkTmlllua3S6RfqOKGAbrI7bEYxk+V5BcnGE33Gf h+eyGRuPkw5kGjo4dV8WOlovPpkkY+5X7bFrL4DJKWCXavgvUGVgF/0LKlT2sVHp Q3mACFSuaol+xF/2cml8eJalNAnKVQSb/rdon+8TdIpxMVf5EhYFvB9uh0RGW0lQ g1AOMYQ23E7cc7k3JPncG+PXIASa2kAfgOvm6SojR+zIXdpbpgDA9fE3RiVCMtDd Fnj8Pvq6VgjQ2jtZmkad =BN6b -----END PGP SIGNATURE-----
--- End Message ---

