Bug#416423: BMP loader integer overflows

2007-03-28 Thread Daniel Baumann
Kees Cook wrote: Attached is the patch being used in Ubuntu. Thanks Kees, upload is on the way.. -- Address:Daniel Baumann, Burgunderstrasse 3, CH-4562 Biberist Email: [EMAIL PROTECTED] Internet: http://people.panthera-systems.net/~daniel-baumann/ -- To UNSUBSCRIBE,

Bug#416423: BMP loader integer overflows

2007-03-27 Thread Kees Cook
Package: xmms Version: 1:1.2.10+20070301-1 Severity: grave Tags: patch, security Two CVEs against XMMS exist: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0653 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0654 Integer overflow in X MultiMedia System (xmms) 1.2.10, and