[Pkg-xfce-devel] xfce4 stable update for CVE-2007-6351

Simon Huggins huggie at earth.li
Wed Jan 30 00:05:50 UTC 2008


On Wed, Jan 30, 2008 at 12:58:08AM +0100, Nico Golde wrote:
> the following CVE (Common Vulnerabilities & Exposures) ids were
> published for xfce4 some time ago.

for xfce4?  These concern libexif.  Did you paste the wrong CVEs?

> CVE-2007-6351[0]:
> | libexif 0.6.16 and earlier allows context-dependent attackers to cause
[..]
> CVE-2007-6352[1]:
> | Integer overflow in libexif 0.6.16 and earlier allows

-- 
----------(  In most countries selling harmful things like   )----------
----------(  drugs is punishable. How come then that people  )----------
Simon ----(    sell Microsoft software and go unpunished?    )---- Nomis
                             Htag.pl 0.0.22
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.alioth.debian.org/pipermail/pkg-xfce-devel/attachments/20080130/901947b8/attachment-0001.pgp 


More information about the Pkg-xfce-devel mailing list