Branches for Warty

Name Status Last Modified Last Commit
lp:ubuntu/warty/imagemagick 1 Development 2009-07-03 19:28:51 UTC
2. * debian/control: - Build-Depends o...

Author: Sebastien Bacher
Revision Date: 2004-08-02 13:01:44 UTC

* debian/control:
  - Build-Depends on libtiff4-dev.

lp:ubuntu/warty-security/imagemagick 1 Development 2009-07-03 19:29:01 UTC
4. * SECURITY UPDATE: Arbitrary code exe...

Author: Martin Pitt
Revision Date: 2006-01-24 14:10:29 UTC

* SECURITY UPDATE: Arbitrary code execution with malicious file names.
* Patch backported from Debian Sid upload (thanks to Daniel Kobras).
* magick/{animate.c,blob.c,display.c,image.c,log.c,montage.c,string.c,
  string_.h}: Implement new utility function FormatMagickStringNumeric()
  to securely expand a user-supplied format string with a single numeric
  argument. Adjust code to use this function where appropriate.
  (CVE-2006-0082) Closes: #345876
* coders/pdf.c,coders/ps.c,magick/delegate.c,magick/delegate.h,
  magick/methods.h: Do not call external delegates with user-supplied
  filename, but with securely named symlinks only to prevent shell command
  injection (CVE-2005-4601). Closes: #345238
* magick/display.c: In DisplayImageCommand(), expand command line before
  allocating ressources based on argc. Patch and analysis thanks to
  Eero Häkkinen. Closes: #345595
* Add missing CVE to previous changelog.

12 of 2 results