Bug#446465: CVE-2007-5378 buffer overflow in tkImgGif.c via crafted gif image

2007-10-13 Thread Nico Golde
Hi, I have an updated package ready to fix this. The patch for it is attached. It will be also archived on: http://people.debian.org/~nion/nmu-diff/tk8.3-8.3.5-9_8.3.5-9.1.patch I wait a few days before uploading this as NMU feel free to update yourself with CVE-2007-5378.diff. Kind regards Nico

Bug#446465: CVE-2007-5378 buffer overflow in tkImgGif.c via crafted gif image

2007-10-13 Thread Nico Golde
Package: tk8.3 Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for tk8.3. CVE-2007-5378[0]: | Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk | Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows | user-assisted att