OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [ GLSA 200607-08 ] GIMP: Buffer overflow

From: Michael Shigorin (mikeosdn.org.ua)
Date: Mon Jul 24 2006 - 11:11:25 CDT


On Sun, Jul 23, 2006 at 05:29:59PM +0200, Sune Kloppenborg Jeppesen wrote:
> -------------------------------------------------------------------
> Package / Vulnerable / Unaffected
> -------------------------------------------------------------------
> 1 media-gfx/gimp < 1.2.12 >= 1.2.12
[...]
> # emerge --sync
> # emerge --ask --oneshot --verbose ">=media-gfx/gimp-1.2.12"

I think it was "2.2.12".

PS: if anyone still needs a minimal patch, here's an extract from
Ubuntu advisory source package:

http://paq.osdn.org.ua/~mike/tmp/gimp-2.2.8-ubuntu-CVE-2006-3404.patch

--
 ---- WBR, Michael Shigorin <mikealtlinux.ru>
  ------ Linux.Kiev http://www.linux.kiev.ua/

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFExPEtbsPDprYMm3IRAtL6AJ0ci/GG8ya0a+Q5iLEKIgsm6i525QCeI/Pa
vojX+YhUxzE9puIJfn9NEKc=
=p7AG
-----END PGP SIGNATURE-----