[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1057-1] libraw security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : libraw
Version        : 0.14.6-2+deb7u2
CVE ID         : CVE-2017-6886 CVE-2017-6887
Debian Bug     : 864183

Some memory corruption bugs were discovered in libraw, a raw image
decoder library, which could be triggered via maliciously crafted
input files to cause denial of service or other unspecified impact.

For Debian 7 "Wheezy", these problems have been fixed in version
0.14.6-2+deb7u2.

We recommend that you upgrade your libraw packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAlmR0IwACgkQnUbEiOQ2
gwKDBhAAgZaVeUH/+4BFQZ7zFTwTrj4JXT8aidcJTKcwlWqESfh+urjAEQ85Uuwe
Cdb6i9nB55WjOtxcdby2s9jCV1PjhBlUvtyaJ9YBByC6tpczf56+9w6KsB3dGcvl
DRqU09UMbTHMmyb8gtAhKz7RhCTr2OhnUl16ddeoWIvbaQldqHKI1jlYqSSfP1Bo
UNeYeKMEPOZEd8oP6j2aQ8+OGV/5H3nAYQJArVDZicsYdxg11YYC+f3o5ls21RBs
5Brdp0hjy+uML9nsr1J2sQiXG7EakAsWG+ksaMTvUQx2IrPgi5cJbPq8tBdW+gm/
5Y8RYTGXfqb+iPYUvozR5pDH8PQ41KtF90VtfG1QVP6HFDsFmzdkZ42Xe300Jf6F
T82swDgqO1g5G3Ma3XucDdyjbs9nvhTEpdBfjTUv0k5vuzrtWzeKijE1FzeCA0Yr
bC9/A/r65lYYQcjoLDZVuTMKYnHCJ/1hCis8xmZ1WSb75j08wUK0V5ndU6ZZRUfD
BPUNlf7JGjS9zDarWZ+k8ZTU3ZFFaPXDIrSMl9AZYmpSP9n+JEHc52Ko1HVqx2Wi
oxCAn5WF5IXS59n0gb2IMyyouexY2aXDHgmlJve3r7g23hl0VcdgaVYEQwwUP3yy
2HuTrrUoP7jS0Z/oLG7PFqnanDGroPb6PQUSNkmPWUw1P3cWjnI=
=iyOm
-----END PGP SIGNATURE-----


Reply to: