Your message dated Mon, 06 Apr 2015 21:32:05 +0000
with message-id <[email protected]>
and subject line Bug#744719: fixed in libgd2 2.0.36~rc1~dfsg-6.1+deb7u1
has caused the Debian Bug report #744719,
regarding libgd2: CVE-2014-2497
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
744719: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744719
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libgd2
Version: 2.0.36~rc1~dfsg-5
Severity: important
Tags: security upstream
Hi,
the following vulnerability was published for libgd2
CVE-2014-2497[0]:
| The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP
| 5.4.26 and earlier, allows remote attackers to cause a denial of
| service (NULL pointer dereference and application crash) via a crafted
| color table in an XPM file.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2014-2497
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1076676
[2] https://bugzilla.novell.com/show_bug.cgi?id=868624
[3]
https://bugs.php.net/patch-display.php?bug_id=66901&patch=bug66901-fix.patch&revision=latest
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libgd2
Source-Version: 2.0.36~rc1~dfsg-6.1+deb7u1
We believe that the bug you reported is fixed in the latest version of
libgd2, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Alessandro Ghedini <[email protected]> (supplier of updated libgd2 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 01 Apr 2015 15:50:38 +0200
Source: libgd2
Binary: libgd-tools libgd2-xpm-dev libgd2-noxpm-dev libgd2-xpm libgd2-noxpm
Architecture: source amd64
Version: 2.0.36~rc1~dfsg-6.1+deb7u1
Distribution: wheezy-security
Urgency: high
Maintainer: GD team <[email protected]>
Changed-By: Alessandro Ghedini <[email protected]>
Description:
libgd-tools - GD command line tools and example code
libgd2-noxpm - GD Graphics Library version 2 (without XPM support)
libgd2-noxpm-dev - GD Graphics Library version 2 (development version)
libgd2-xpm - GD Graphics Library version 2
libgd2-xpm-dev - GD Graphics Library version 2 (development version)
Closes: 744719
Changes:
libgd2 (2.0.36~rc1~dfsg-6.1+deb7u1) wheezy-security; urgency=high
.
* Fix NULL pointer dereference when reading XPM files with a
crafted color table as per CVE-2014-2497 (Closes: #744719)
* Fix buffer read overflow when reading invalid GIF files
as per CVE-2014-9709
Checksums-Sha1:
5674b4b477e0a9e2f70acac0d9c844b6fe2ba23b 2411
libgd2_2.0.36~rc1~dfsg-6.1+deb7u1.dsc
e93c43f3c2283c6fe09793ac06a4a106374e0cb3 761899
libgd2_2.0.36~rc1~dfsg.orig.tar.gz
983c32fc0948fae1a3ee45db2aa58da364446f77 27827
libgd2_2.0.36~rc1~dfsg-6.1+deb7u1.debian.tar.gz
68784425d631654ffcb26db08df5e3e1bd493983 169030
libgd-tools_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
3d19f12c68b2eab12814a48e44780c2d1148aeec 373706
libgd2-xpm-dev_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
f87b62b147f16917d3f90732dc4c4ab630c92a19 371014
libgd2-noxpm-dev_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
d1c42252d1cb491e5648a09d58b295a07feff853 232634
libgd2-xpm_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
5707a423ff76c52a8a5e51e9b87d3e1231e6e3e1 230254
libgd2-noxpm_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
Checksums-Sha256:
80a055b10a0684b2ca4561fb980fa2dc4cc58696c2788463350572b13c85bfb4 2411
libgd2_2.0.36~rc1~dfsg-6.1+deb7u1.dsc
919df21310ad4a8b6155df01411138110589cc6c50b1bc414dc62aebb0a7f41a 761899
libgd2_2.0.36~rc1~dfsg.orig.tar.gz
08836dc82405ad76fc7ea003ebbb25c112e1b7b91f805d044bfb85b238e686ed 27827
libgd2_2.0.36~rc1~dfsg-6.1+deb7u1.debian.tar.gz
e463df1f08b079c50ae87d5956f5108450573fb43e8f7b2b3f6e633b8cff6220 169030
libgd-tools_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
7d1d20cc510ee470ecce8e2de5c831d812d7058b7db94cb0373fb40d2c02de9a 373706
libgd2-xpm-dev_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
134165b1499bec0ea39bce6ca0673491ebfa27f4a7de8a17c3b8c5d913d7496f 371014
libgd2-noxpm-dev_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
3cd6852a1fff4ddc24753e0108162c3876f78670ffc2b601a0954c434ebcdb3c 232634
libgd2-xpm_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
f307c1d1ca2dfa4ad38dbc39155bb0ec27f621827adf6173eba13a6436c6d9b3 230254
libgd2-noxpm_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
Files:
a407fc77ff5089266bbf911a06dcea73 2411 graphics optional
libgd2_2.0.36~rc1~dfsg-6.1+deb7u1.dsc
0f4d2fa45627af0e87fcb74f653b66dd 761899 graphics optional
libgd2_2.0.36~rc1~dfsg.orig.tar.gz
71c95079dd1c876eca6f7d8bcbd1896a 27827 graphics optional
libgd2_2.0.36~rc1~dfsg-6.1+deb7u1.debian.tar.gz
de982362b7bf1228e5be47f974e7b714 169030 graphics optional
libgd-tools_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
35b0ef40129daf10708e2db6d16c3236 373706 libdevel optional
libgd2-xpm-dev_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
e819ec5a17f8af0acca225c861270c0a 371014 libdevel optional
libgd2-noxpm-dev_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
e16af3ed7d66bddcf5016b14b9237a2d 232634 libs optional
libgd2-xpm_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
fe90ef6c10aa3e43c45733e8247f626c 230254 libs optional
libgd2-noxpm_2.0.36~rc1~dfsg-6.1+deb7u1_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJVIo4AAAoJEK+lG9bN5XPLopoP/j0WYpSZRTN717gyZi9XsS+W
vb+G+w7acjzwkoxp3yY/fR2UxlIHbOUIgmWFgPe7gsKJ15WgRTJiKvHLVivGIqKx
VIOatUYi+YKY8sqtkvmE2xLLzn3jYlEoG4oemfjXaG9dgRfjZKZNpCzLzmCnAHvM
VdiWCGsyholTdQP4THcVxHEu/OGMbqy5g3WciZihnrtZwoZw/JmM7FFjI1ZuogeA
aYQCjinhgm532eLTRZakfdckgCzMC/kC6juvF7LzAAWF/L7IpW8VJgvmS8/bPEOT
KtCibzWIfCJXfwvPCo9wiK/+oShfVAeWh25SsBWq/3tsox+WoVxPMo9tczFHkCne
BLo2hhH0TpfN7V01qfD11RCxYMvyeCih/MY2hsgtjHg9xtX4Jb0xhvQygoK1bbOR
rLae7W6N14WesYcphSyb48O8LxC2Vv8MQbSjHl/SYQRKzdEhJs10wvwMep0kQl0R
QTa0yU58lFFTI//mYYaPYyCT+CHPFyE6y6khOC+fudfo4SazDXD/F8vhcwk86ZVM
aoAyFLRI6zMVl82m8LyOH0/IrdDSi/t5wjvjztXDNehvCAl63w3wWgCIOuk0EV2n
HFvpz7CviadB7iJmBkgaZjvyGL2Jl6muMdcVdmM5RpUxBA7lboLsLMZV31D+sdHM
kp5Rk27vRFH0vdFqImxf
=SQz6
-----END PGP SIGNATURE-----
--- End Message ---