r52282 - in /desktop/jessie/gtk+2.0/debian: changelog patches/099_CVE-2013-7447.patch patches/series

sthibault at users.alioth.debian.org sthibault at users.alioth.debian.org
Mon Mar 20 22:03:59 UTC 2017


Author: sthibault
Date: Mon Mar 20 22:03:59 2017
New Revision: 52282

URL: http://svn.debian.org/wsvn/pkg-gnome/?sc=1&rev=52282
Log:
CVE-2013-7447 (Closes: #799275) and +deb8u1 upload

Added:
    desktop/jessie/gtk+2.0/debian/patches/099_CVE-2013-7447.patch
Modified:
    desktop/jessie/gtk+2.0/debian/changelog
    desktop/jessie/gtk+2.0/debian/patches/series

Modified: desktop/jessie/gtk+2.0/debian/changelog
URL: http://svn.debian.org/wsvn/pkg-gnome/desktop/jessie/gtk%2B2.0/debian/changelog?rev=52282&op=diff
==============================================================================
--- desktop/jessie/gtk+2.0/debian/changelog	[utf-8] (original)
+++ desktop/jessie/gtk+2.0/debian/changelog	[utf-8] Mon Mar 20 22:03:59 2017
@@ -1,3 +1,9 @@
+gtk+2.0 (2.24.25-3+deb8u1) jessie; urgency=medium
+
+  * CVE-2013-7447 (Closes: #799275)
+
+ -- Moritz Mühlenhoff <jmm at debian.org>  Thu, 17 Mar 2016 00:17:18 +0100
+
 gtk+2.0 (2.24.25-3) unstable; urgency=medium
 
   * 0002-gdk-Fix-GdkWindowFilter-internal-refcounting.patch

Added: desktop/jessie/gtk+2.0/debian/patches/099_CVE-2013-7447.patch
URL: http://svn.debian.org/wsvn/pkg-gnome/desktop/jessie/gtk%2B2.0/debian/patches/099_CVE-2013-7447.patch?rev=52282&op=file
==============================================================================
--- desktop/jessie/gtk+2.0/debian/patches/099_CVE-2013-7447.patch	(added)
+++ desktop/jessie/gtk+2.0/debian/patches/099_CVE-2013-7447.patch	[utf-8] Mon Mar 20 22:03:59 2017
@@ -0,0 +1,30 @@
+From 894b1ae76a32720f4bb3d39cf460402e3ce331d6 Mon Sep 17 00:00:00 2001
+From: Matthias Clasen <mclasen at redhat.com>
+Date: Sat, 29 Jun 2013 22:06:54 -0400
+Subject: Avoid integer overflow
+
+Use g_malloc_n in gdk_cairo_set_source_pixbuf when allocating
+a large block of memory, to avoid integer overflow.
+
+Pointed out by Bert Massop in
+https://bugzilla.gnome.org/show_bug.cgi?id=703220
+---
+ gdk/gdkcairo.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/gdk/gdkcairo.c b/gdk/gdkcairo.c
+index 19bed04..2e1d8dc 100644
+--- a/gdk/gdkcairo.c
++++ b/gdk/gdkcairo.c
+@@ -213,7 +213,7 @@ gdk_cairo_set_source_pixbuf (cairo_t         *cr,
+     format = CAIRO_FORMAT_ARGB32;
+ 
+   cairo_stride = cairo_format_stride_for_width (format, width);
+-  cairo_pixels = g_malloc (height * cairo_stride);
++  cairo_pixels = g_malloc_n (height, cairo_stride);
+   surface = cairo_image_surface_create_for_data ((unsigned char *)cairo_pixels,
+                                                  format,
+                                                  width, height, cairo_stride);
+-- 
+cgit v0.12
+

Modified: desktop/jessie/gtk+2.0/debian/patches/series
URL: http://svn.debian.org/wsvn/pkg-gnome/desktop/jessie/gtk%2B2.0/debian/patches/series?rev=52282&op=diff
==============================================================================
--- desktop/jessie/gtk+2.0/debian/patches/series	[utf-8] (original)
+++ desktop/jessie/gtk+2.0/debian/patches/series	[utf-8] Mon Mar 20 22:03:59 2017
@@ -14,3 +14,4 @@
 061_use_pdf_as_default_printing_standard.patch
 065_gir_set_packages.patch
 098_multiarch_module_path.patch
+099_CVE-2013-7447.patch




More information about the pkg-gnome-commits mailing list