Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 10 ocaml-camlimages-3.0.1-3 Critical Integer Overflow

fedora
Calendar Grey November 10, 2009
Dist Fedora Esm H88
Fedora's recent patch improves PNG processing in the ocaml-camlib library, boosting both security measures and operational efficiency.
Fix handling of oversized TIFF images.

Summary

CamlImages is an image processing library for Objective CAML, which provides:

basic functions for image processing and loading/saving, various image file

formats (hence providing a translation facility from format to format),

and an interface with the Caml graphics library allows to display images

in the Graphics module screen and to mix them with Caml drawings

In addition, the library can handle huge images that cannot be (or can hardly

be) stored into the main memory (the library then automatically creates swap

files and escapes them to reduce the memory usage).

Update Information:

Fix handling of oversized TIFF images.

Change Log

* Fri Oct 16 2009 Richard W.M. Jones - 3.0.1-3.fc10.3 - ocaml-camlimages: TIFF reader multiple integer overflows (CVE 2009-3296 / RHBZ#528732). * Fri Jul 3 2009 Richard W.M. Jones - 3.0.1-3.fc10.2 - ocaml-camlimages: PNG reader multiple integer overflows (CVE 2009-2295 / RHBZ#509531). * Mon Nov 3 2008 Richard W.M. Jones - 3.0.1-3 - +BR gtk2-devel. - +BR ocaml-x11. * Mon Nov 3 2008 Richard W.M. Jones - 3.0.1-1 - Home page moved (fixes rhbz 468158). - New upstream version 3.0.1 and multiple build fixes for this. - License is really LGPLv2 with the OCaml linking exception. - Removed the DESTDIR patch. - Build tiff support. - Run it through rpmlint and fix all problems.

References


[ 1 ] Bug #528732 - CVE-2009-3296 ocaml-camlimages: TIFF reader multiple integer overflows https://bugzilla.redhat.com/show_bug.cgi?id=528732

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update ocaml-camlimages' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ocaml-camlimages
Product: Fedora 10
Version: 3.0.1
Release: 3.fc10.3
URL: Summary : OCaml image processing library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here