[pkg-GD-devel] Bug#840806: closed by Ondřej Surý <ondrej at debian.org> (Bug#840806: fixed in libgd2 2.2.3-87-gd0fec80-1)

Salvatore Bonaccorso carnil at debian.org
Mon Oct 31 13:16:00 UTC 2016


Control: reopen -1 

Hi Ondřej,

While updating the security-tracker information I noticed:

On Mon, Oct 31, 2016 at 10:21:15AM +0000, Debian Bug Tracking System wrote:
[...]
>     + [CVE-2016-6911]: invalid read in gdImageCreateFromTiffPtr()
[...]

For the recently uploaded Version 2.2.3-87-gd0fec80-1. But comparing
this with the patch applied in jessie-security, named
0020-Fix-invalid-read-in-gdImageCreateFromTiffPtr.patch

Is this patch missing for the unstable upload?

I'm reopening the bug just to be on the safe side, but happy to be
corrected if I'm wrong!

Regards,
Salvatore



More information about the pkg-GD-devel mailing list