[El-errata] ELSA-2007-0513 Moderate: Enterprise Linux 4 gimp security update
el-errata at oss.oracle.com
el-errata at oss.oracle.com
Wed Sep 26 15:48:02 PDT 2007
Enterprise Linux Security Advisory ELSA-2007-0513
https://rhn.redhat.com/errata/RHSA-2007-0513.html
The following updated rpms for Enterprise Linux 4 have been uploaded to
the Unbreakable Linux Network:
i386:
gimp-2.0.5-7.0.7.el4.i386.rpm
gimp-devel-2.0.5-7.0.7.el4.i386.rpm
x86_64:
gimp-2.0.5-7.0.7.el4.x86_64.rpm
gimp-devel-2.0.5-7.0.7.el4.x86_64.rpm
SRPMS:
http://oss.oracle.com/el4/SRPMS-updates/gimp-2.0.5-7.0.7.el4.src.rpm
Description of changes:
[2.0.5-7.0.7.el4]
- validate bytesperline header field when loading PCX files (#247571)
[2.0.5-7.0.6.el4]
- replace gimp_error() by gimp_message()/gimp_quit() in a few plugins so
they
don't crash but gracefully exit when encountering error conditions
- fix endianness issues in the PSP plugin to avoid it doing (seemingly)
endless
loops when loading images
- fix endianness issues in the PCX plugin which cause it to not detect
corrupt
images
[2.0.5-7.0.5.el4]
- add safeguard to avoid crashes while loading corrupt PSD images (#247571,
patch by Raphaël Quinet)
[2.0.5-7.0.4.el4]
- don't divide by zero when loading a layer or mask with zero width or
height
when loading PSD images (#247571, patch by Sven Neumann)
[2.0.5-7.0.3.el4]
- add ChangeLog entry to psd-invalid-dimensions patch (#247571)
- validate size values read from files before using them to allocate
memory in
various file plugins (#247571, patch by Mukund Sivaraman and Raphaël
Quinet)
- detect invalid image data when reading files in several plugins (#247571,
patch by Sven Neumann and Raphaël Quinet, adapted for 2.0.5)
- validate size values read from files before using them to allocate
memory in
the PSD and sunras plugins (#247571, patch by Mukund Sivaraman)
- convert spec file to UTF-8
[2.0.5-7.0.2.el4]
- use upstream PSD fix by Sven Neumann (#244407)
[2.0.5-7.0.1.el4]
- refuse to open PSD files with insanely large dimensions (#244407)
More information about the El-errata
mailing list