From c38cb83747f19bf8e2f2f879b56d6c9ac38efca1 Mon Sep 17 00:00:00 2001 From: Thorsten Alteholz Date: Mon, 6 Apr 2020 08:32:05 +0200 Subject: dla 2165 --- english/lts/security/2020/dla-2165.data | 10 ++++++++++ english/lts/security/2020/dla-2165.wml | 23 +++++++++++++++++++++++ 2 files changed, 33 insertions(+) create mode 100644 english/lts/security/2020/dla-2165.data create mode 100644 english/lts/security/2020/dla-2165.wml diff --git a/english/lts/security/2020/dla-2165.data b/english/lts/security/2020/dla-2165.data new file mode 100644 index 00000000000..f21ebffc903 --- /dev/null +++ b/english/lts/security/2020/dla-2165.data @@ -0,0 +1,10 @@ +DLA-2165-1 apng2gif +2020-3-31 +CVE-2017-6960 +apng2gif +yes +yes +no + +#use wml::debian::security + diff --git a/english/lts/security/2020/dla-2165.wml b/english/lts/security/2020/dla-2165.wml new file mode 100644 index 00000000000..92586f4b3e1 --- /dev/null +++ b/english/lts/security/2020/dla-2165.wml @@ -0,0 +1,23 @@ +LTS security update + + +

An issue has been found in apng2gif, a tool for converting APNG images to +animated GIF format.

+ +

One of the function contained an integer overflow resulting in a +heap-based buffer over-read.

+ + +

For Debian 8 Jessie, this problem has been fixed in version +1.5-3+deb8u1.

+ +

We recommend that you upgrade your apng2gif packages.

+ +

Further information about Debian LTS security advisories, how to apply +these updates to your system and frequently asked questions can be +found at: https://wiki.debian.org/LTS

+
+ +# do not modify the following line +#include "$(ENGLISHDIR)/lts/security/2020/dla-2165.data" +# $Id: $ -- cgit v1.2.3