[DebianGIS-dev] Bug#474051: libhdf5-serial-dev: libhdf5 appears to write uninitialized memory to file

2008-04-03 Thread Rafael Laboissiere
* Jason Kraftcheck [EMAIL PROTECTED] [2008-04-02 19:04]: Package: libhdf5-serial-dev Version: 1.6.5-3 Severity: grave Tags: security Justification: user security hole valgrind reports writes of unitialized memory in hdf5 library. This could be a serious security issue, depending on

[DebianGIS-dev] Bug#474051: libhdf5-serial-dev: libhdf5 appears to write uninitialized memory to file

2008-04-03 Thread Jason Kraftcheck
Rafael Laboissiere wrote: I cannot reproduce the problem above with libhdf5-serial-1.6.6, version 1.6.6-4 (currently in unstable). Using the C program that you provided, I get the following output from valgrind: ==11598== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 8 from 1)

[DebianGIS-dev] Bug#474051: libhdf5-serial-dev: libhdf5 appears to write uninitialized memory to file

2008-04-02 Thread Jason Kraftcheck
Package: libhdf5-serial-dev Version: 1.6.5-3 Severity: grave Tags: security Justification: user security hole valgrind reports writes of unitialized memory in hdf5 library. This could be a serious security issue, depending on what that memory contains. This can be reproduced by running almost