Fedora alert FEDORA-2009-10594 (ocaml-camlimages)
| From: | updates@fedoraproject.org | |
| To: | fedora-package-announce@redhat.com | |
| Subject: | [SECURITY] Fedora 11 Update: ocaml-camlimages-3.0.1-7.fc11.3 | |
| Date: | Tue, 10 Nov 2009 17:44:02 +0000 | |
| Message-ID: | <20091110174402.3BED310F88E@bastion2.fedora.phx.redhat.com> | |
| Archive‑link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10594 2009-10-21 00:08:31 -------------------------------------------------------------------------------- Name : ocaml-camlimages Product : Fedora 11 Version : 3.0.1 Release : 7.fc11.3 URL : http://gallium.inria.fr/camlimages/ Summary : OCaml image processing library Description : CamlImages is an image processing library for Objective CAML, which provides: basic functions for image processing and loading/saving, various image file formats (hence providing a translation facility from format to format), and an interface with the Caml graphics library allows to display images in the Graphics module screen and to mix them with Caml drawings In addition, the library can handle huge images that cannot be (or can hardly be) stored into the main memory (the library then automatically creates swap files and escapes them to reduce the memory usage). -------------------------------------------------------------------------------- Update Information: Fix handling of oversized TIFF images. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 16 2009 Richard W.M. Jones <rjones@redhat.com> - 3.0.1-7.fc11.3 - ocaml-camlimages: TIFF reader multiple integer overflows (CVE 2009-3296 / RHBZ#528732). * Fri Jul 3 2009 Richard W.M. Jones <rjones@redhat.com> - 3.0.1-7.fc11.2 - ocaml-camlimages: PNG reader multiple integer overflows (CVE 2009-2295 / RHBZ#509531). -------------------------------------------------------------------------------- References: [ 1 ] Bug #528732 - CVE-2009-3296 ocaml-camlimages: TIFF reader multiple integer overflows https://bugzilla.redhat.com/show_bug.cgi?id=528732 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ocaml-camlimages' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...
