Re: Sufficient patch for CVE-2006-0082

Albert Chin <[email protected]> Wed, 1 Mar 2006 11:57:44 -0600
Newsgroups gmane.comp.video.graphicsmagick.core
Message-ID <[email protected]>
On Wed, Mar 01, 2006 at 05:31:09PM +0100, Daniel Kobras wrote:
> On Wed, Mar 01, 2006 at 09:57:59AM -0600, Albert Chin wrote:
> > Is the attached patch ok for CVE-2006-0082? It is taken from Gentoo:
> >   http://www.gentoo.org/security/en/glsa/glsa-200602-13.xml
> 
> This patch breaks multi-frame support, and misses a number of similar
> code paths. The attached patch is applied to the Debian package of
> 1.1.7.
>
> ...
>
> Format string security fix, addressing CVE-2005-0397 and further related
> problems. Introduces new function FormatStringNumeric() that allows a
> single numeric format substitution on untrusted user input.

Ok, thanks. Looking at the description of CVE-2005-0397 and
CVE-2006-0082, it would seem applying this patch for CVE-2005-0397
solves CVE-2006-0082 as well.

-- 
albert chin ([email protected])


-------------------------------------------------------
This SF.Net email is sponsored by xPML, a groundbreaking scripting language
that extends applications into web and mobile media. Attend the live webcast
and join the prime developer group breaking into this new coding territory!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642