[El-errata] ELSA-2007-0513 Moderate: Enterprise Linux 4 gimp security update

el-errata at oss.oracle.com el-errata at oss.oracle.com
Wed Sep 26 15:48:02 PDT 2007


Enterprise Linux Security Advisory ELSA-2007-0513

https://rhn.redhat.com/errata/RHSA-2007-0513.html

The following updated rpms for Enterprise Linux 4 have been uploaded to 
the Unbreakable Linux Network:

i386:
gimp-2.0.5-7.0.7.el4.i386.rpm
gimp-devel-2.0.5-7.0.7.el4.i386.rpm

x86_64:
gimp-2.0.5-7.0.7.el4.x86_64.rpm
gimp-devel-2.0.5-7.0.7.el4.x86_64.rpm


SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/gimp-2.0.5-7.0.7.el4.src.rpm

Description of changes:

[2.0.5-7.0.7.el4]
- validate bytesperline header field when loading PCX files (#247571)

[2.0.5-7.0.6.el4]
- replace gimp_error() by gimp_message()/gimp_quit() in a few plugins so 
they
  don't crash but gracefully exit when encountering error conditions
- fix endianness issues in the PSP plugin to avoid it doing (seemingly) 
endless
  loops when loading images
- fix endianness issues in the PCX plugin which cause it to not detect 
corrupt
  images

[2.0.5-7.0.5.el4]
- add safeguard to avoid crashes while loading corrupt PSD images (#247571,
  patch by Raphaël Quinet)

[2.0.5-7.0.4.el4]
- don't divide by zero when loading a layer or mask with zero width or 
height
  when loading PSD images (#247571, patch by Sven Neumann)

[2.0.5-7.0.3.el4]
- add ChangeLog entry to psd-invalid-dimensions patch (#247571)
- validate size values read from files before using them to allocate 
memory in
  various file plugins (#247571, patch by Mukund Sivaraman and Raphaël 
Quinet)
- detect invalid image data when reading files in several plugins (#247571,
  patch by Sven Neumann and Raphaël Quinet, adapted for 2.0.5)
- validate size values read from files before using them to allocate 
memory in
  the PSD and sunras plugins (#247571, patch by Mukund Sivaraman)
- convert spec file to UTF-8

[2.0.5-7.0.2.el4]
- use upstream PSD fix by Sven Neumann (#244407)

[2.0.5-7.0.1.el4]
- refuse to open PSD files with insanely large dimensions (#244407)





More information about the El-errata mailing list