mandriva: updated netpbm packages fix vulnerability - the community's center for security
mandriva: updated netpbm packages fix vulnerability - the community's center for security
the central voice for linux and open source security news
home
news topics
advisories
howtos
features newsletters
about
register
ls.comadvisoriesfeatureshowtoslinux eventsnewsnewsletterspresssecurity dictionarysecurity tips
welcome!
sign up!
engarde community
login
polls
when was the last time you read a book on linux like "linux firewalls?"
i'm reading right now!
this past month.
a couple months ago.
ealier in the year.
last year.
read? books? i have the internet.
security center
book reviews
security dictionary
security tips
selinux
white papers
community
linux events
linux user groups
link to us
featured blogs
danwalsh livejournal
tenable network security
mayank sharma: ibm
advisories
ubuntu: flac vulnerabilitymandriva: updated kernel packages fix multipleredhat: moderate: ruby security update
latest newsletters
linux security week: november 12th, 2007linux advisory watch: november 9th, 2007
subscribe
linuxsecurity newsletters
e-mail:
choose lists:
both lists
newsletter
security advisories
about our newsletters
rss feeds
get the linuxsecurity news you want faster with rss
powered by
mandriva: updated netpbm packages fix vulnerability
user rating:
how can i rate this item?
posted by benjamin d. thomas
a function in the jasper jpeg-2000 library before 1.900 could allow
a remote user-assisted attack to cause a crash and possibly corrupt
the heap via malformed image files.
netpbm contains an embedded copy of libjasper and as such is vulnerable
to this issue.
updated packages have been patched to prevent this issue.
_______________________________________________________________________
mandriva linux security advisory mdksa-2007:209
http://www.mandriva.com/security/
_______________________________________________________________________
package : netpbm
date : november 5, 2007
affected: 2007.0, 2007.1, 2008.0, corporate 4.0
_______________________________________________________________________
problem description:
a function in the jasper jpeg-2000 library before 1.900 could allow
a remote user-assisted attack to cause a crash and possibly corrupt
the heap via malformed image files.
netpbm contains an embedded copy of libjasper and as such is vulnerable
to this issue.
updated packages have been patched to prevent this issue.
_______________________________________________________________________
references:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-2721
_______________________________________________________________________
updated packages:
mandriva linux 2007.0:
21887e239c40eeb005a3e4e461373ac1 2007.0/i586/libnetpbm10-10.34-2.1mdv2007.0.i586.rpm
1f767210d43a7bd19c362834ac5fd6b2 2007.0/i586/libnetpbm10-devel-10.34-2.1mdv2007.0.i586.rpm
65c5b22aeafd72ed0086ad07aff890e2 2007.0/i586/libnetpbm10-static-devel-10.34-2.1mdv2007.0.i586.rpm
ecd48c6ecf0f9e89da3027e16193471d 2007.0/i586/netpbm-10.34-2.1mdv2007.0.i586.rpm
466e8fff6fedb3faa648ddd7d3979479 2007.0/srpms/netpbm-10.34-2.1mdv2007.0.src.rpm
mandriva linux 2007.0/x86_64:
f88df67b1231807cfc92da43d726cf1d 2007.0/x86_64/lib64netpbm10-10.34-2.1mdv2007.0.x86_64.rpm
6aac7b4d66e58ddc46f99e143599994d 2007.0/x86_64/lib64netpbm10-devel-10.34-2.1mdv2007.0.x86_64.rpm
9a432d9f23f5fbe9176bacfcdbcff498 2007.0/x86_64/lib64netpbm10-static-devel-10.34-2.1mdv2007.0.x86_64.rpm
d1ae683dcf913acf169ae7085b6d95b1 2007.0/x86_64/netpbm-10.34-2.1mdv2007.0.x86_64.rpm
466e8fff6fedb3faa648ddd7d3979479 2007.0/srpms/netpbm-10.34-2.1mdv2007.0.src.rpm
mandriva linux 2007.1:
1953ec670d8a0e440bc95191d5558b2c 2007.1/i586/libnetpbm10-10.34-4.1mdv2007.1.i586.rpm
43714e3f4b74f76837525ba0d0fdab79 2007.1/i586/libnetpbm10-devel-10.34-4.1mdv2007.1.i586.rpm
4c5b65bd3b26ccd89ab3ae76ec170ed8 2007.1/i586/libnetpbm10-static-devel-10.34-4.1mdv2007.1.i586.rpm
43df801c9cf8ffc3fab1110e86e5e860 2007.1/i586/netpbm-10.34-4.1mdv2007.1.i586.rpm
4f99de1583ced224abec7c3655c5c45c 2007.1/srpms/netpbm-10.34-4.1mdv2007.1.src.rpm
mandriva linux 2007.1/x86_64:
a47e67ca11a0ff57b098606b9ab3736d 2007.1/x86_64/lib64netpbm10-10.34-4.1mdv2007.1.x86_64.rpm
a3fb4046e81e9d445ca12e54c93dc623 2007.1/x86_64/lib64netpbm10-devel-10.34-4.1mdv2007.1.x86_64.rpm
957b5ff4c085869efccc48e0fb9ece4e 2007.1/x86_64/lib64netpbm10-static-devel-10.34-4.1mdv2007.1.x86_64.rpm
b49ebc2834eabe434f978980c4aac27d 2007.1/x86_64/netpbm-10.34-4.1mdv2007.1.x86_64.rpm
4f99de1583ced224abec7c3655c5c45c 2007.1/srpms/netpbm-10.34-4.1mdv2007.1.src.rpm
mandriva linux 2008.0:
2d661470a39b29a3cf3145429f376ffa 2008.0/i586/libnetpbm-devel-10.34-8.1mdv2008.0.i586.rpm
0b75d5cd47802f8e151f139939412915 2008.0/i586/libnetpbm-static-devel-10.34-8.1mdv2008.0.i586.rpm
99c9d2d0ae583f66650e82348c204d17 2008.0/i586/libnetpbm10-10.34-8.1mdv2008.0.i586.rpm
b53bd70e674044f490c0992e67d9e6a2 2008.0/i586/netpbm-10.34-8.1mdv2008.0.i586.rpm
a199571023b5ff682fe175df9891bb62 2008.0/srpms/netpbm-10.34-8.1mdv2008.0.src.rpm
mandriva linux 2008.0/x86_64:
b02c0316babea8891ba5e4eaa652ea86 2008.0/x86_64/lib64netpbm-devel-10.34-8.1mdv2008.0.x86_64.rpm
d0ab54cdb9987e203da168e83607bd7c 2008.0/x86_64/lib64netpbm-static-devel-10.34-8.1mdv2008.0.x86_64.rpm
d077471c00e0138b7d89f613d3a0a9bd 2008.0/x86_64/lib64netpbm10-10.34-8.1mdv2008.0.x86_64.rpm
8d5d64a1b5f25520924cac520370a09f 2008.0/x86_64/netpbm-10.34-8.1mdv2008.0.x86_64.rpm
a199571023b5ff682fe175df9891bb62 2008.0/srpms/netpbm-10.34-8.1mdv2008.0.src.rpm
corporate 4.0:
b1a4f3587b4a6721ce8cade1bfdd0f61 corporate/4.0/i586/libnetpbm10-10.29-1.4.20060mlcs4.i586.rpm
7cf3a27f15a679bcb147c3167e412411 corporate/4.0/i586/libnetpbm10-devel-10.29-1.4.20060mlcs4.i586.rpm
6c49683e1be0d013577fc4f0185976c9 corporate/4.0/i586/libnetpbm10-static-devel-10.29-1.4.20060mlcs4.i586.rpm
10a82429f9d6c8fff3b77ecaf98c49d7 corporate/4.0/i586/netpbm-10.29-1.4.20060mlcs4.i586.rpm
77301f132a6ec813c5c843da14e2619f corporate/4.0/srpms/netpbm-10.29-1.4.20060mlcs4.src.rpm
corporate 4.0/x86_64:
9934c79e19288deb5606b55b41286488 corporate/4.0/x86_64/lib64netpbm10-10.29-1.4.20060mlcs4.x86_64.rpm
af8a4672eba83f45cd280068ca61f43c corporate/4.0/x86_64/lib64netpbm10-devel-10.29-1.4.20060mlcs4.x86_64.rpm
f7195edb42c216ffbe92a4891a3163e9 corporate/4.0/x86_64/lib64netpbm10-static-devel-10.29-1.4.20060mlcs4.x86_64.rpm
26ae01a21401477c2ea0179718e14fe2 corporate/4.0/x86_64/netpbm-10.29-1.4.20060mlcs4.x86_64.rpm
77301f132a6ec813c5c843da14e2619f corporate/4.0/srpms/netpbm-10.29-1.4.20060mlcs4.src.rpm
_______________________________________________________________________
to upgrade automatically use mandrivaupdate or urpmi. the verification
of md5 checksums and gpg signatures is performed automatically for you.
all packages are signed by mandriva for security. you can obtain the
gpg public key of the mandriva security team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458a98
you can view other update advisories for mandriva linux at:
http://www.mandriva.com/security/advisories
if you want to report vulnerabilities, please contact
security_(at)_mandriva.com
_______________________________________________________________________
type bits/keyid date user id
pub 1024d/22458a98 2000-07-10 mandriva security team
< prev
next >
partner:
latest features
review: linux firewallsstate of linux security surveyunderstand: fork bombing attackreview: ruby by examplewhat makes metasploit tick?review: computer security basics 2nd editionreview: practical packet analysis
yesterday's edition
apparmor's security goals
interview with the author of "linux firewalls"
firefox security flaw affecting gmail's users
home |
about us |
advertise |
legal notice |
rss |
guardian digital
(c)copyright 2007 guardian digital, inc. all rights reserved.
Acceuil
suivante
mandriva: updated netpbm packages fix vulnerability - the community's center for security Mandriva: Updated xen packages fix multiple vulnerabilities - The ... Security Fix Live - washingtonpost.com MSN Fix .... besoin de renseignements URGENT The Gossip Fix ColdFusion 8.0 Cumulative Hot Fix 1 com.fixのご紹介 オプションパーツのご注文 Outlook Express Repair - recovery of corrupted DBX files. Repair ... Help Key: How-To Fix an iPod that Won’t Boot Secuser.com - Utilitaires de désinfection (removal tools) BigFix :: Home sugah + fix sugah - Achat en ligne sur HawaiiSurf : le magasin des ... ToolsSalon.com: Fix It Power Rechargeable Halogen Spotlight - 6 Ways to Fix a Confused Information Architecture (Jakob Nielsen's ... Growing a Business Website: Fix the Basics First (Jakob Nielsen's ... AppleInsider Apple releases iMac freezing fix, MacBook Pro ... FrSIRT - Fix and Chips CMS Multiple Parameter Handling Client-Side ... fix-fmlt.mylivepage.com : Fix-fm EMA / 88 Macworld: Mac 911: Bugs & Fixes: Fix Leopard glitches Download details: Autoplay Repair Wizard Download details: SafeDisc Windows XP Fix for Microsoft Games How to Perform a Windows XP Repair Install Toiletology 101: Toilet Repair HELP!! Do-It-Yourself InkJet and Laser Printer Repair (HP, Apple, Epson ... [SpoilerFix.com] SpoilerFix.com messages to the visitors! Digg - Troubleshooting 101 : How to fix the family computer and ... Digg - Don’t Throw Out Your Broken iPod; Fix It via the Web DailyTech - Apple Releases Fix for iMac Freeze Issue, Updates MacBooks GigaByte 8INXP / Fix AGP-PCI - X86-secret.com Forums Fixitnow.com Samurai Appliance Repair Man DIY Home Improvement Information DoItYourself.com WMP Scripting Fix Shoot Me Again Webzine. Meet Fix Fix It Utilities : un logiciel de Ontrack WinSock XP Fix 1.2 Freeware download page - tested and reviewed ... Forum Snow-FR -> [AVIS] Fix SP SecurityFocus FIX - Définition - Sospc-en-ligne.com Corrupt ZIP File Repair Tool - Repair corrupt ZIP File(s) and ... COLOR VISION Logiciel Print Fix Pro Suite (New) sur Digit-Photo.com Access Database Repair and Recovery: fix corrupt mdb repair file Press Room: Press Releases - AutoTrader.com Fixit Guide Series - DIY Mac & iPod Repair WinXpFix.com Home page (wixpfix.com) Windows xp news, Tips, Free ... YouTube - coldplay fix you Babycoque Créatis.Fix BÉBÉ CONFORT pour poussette Loola ... How to Fix No Child Left Behind - TIME Lauren Fix: The Car Coach ~ Automotive Expert JScreenFix - Fix stuck pixels and screen burn-in Radars fix et delais de reception - Sécurité Radars & Co - FORUM ... Kitco Inc. - Past Historical London Fix Paul Fix Fix 4 RSO FixMyXP.com - Your One Stop Windows XP Fix It Site Outlook Recovery Tool to Fix PST File - PST Repair Software The new urgency to fix online privacy Tech News on ZDNet Appliance Repair Aid Complete Microwave Oven Troubleshooting, Repair and Information Modernfix.com fix buffalo today pandafix