[sflack-security] libexif (SFSA:2007-164-01)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


[sflack-security] libexif (SFSA:2007-164-01)

New libexif packages are available for Sflack 11.0, and -current to
fix a crash and potential security issue.

More details about this issue may be found in the Common
Vulnerabilities and Exposures (CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4168

Here are the details from the Sflack 11.0 ChangeLog:
+--------------------------+
l/libexif-0.6.16-x86_64-1_sflack11.0.tgz: Upgraded to libexif-0.6.16.
An integer overflow in libexif can crash applications that use the library
on malformed images. The upstream advisory indicates that this flaw could
also be used to execute arbitrary code in the context of the user, but no
exploit is known (by us) to exist among iDefense's researchers or in the
wild. But, as a crash bug and heap overflow one must suppose that the
possibility exists.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4168
(* Security fix *)
+--------------------------+


Where to find the new packages:
+-----------------------------+

See the "Get Sflack" section on http://sflack.com for
additional mirror sites near you.

Updated package for Sflack 11.0:
ftp://ftp.sflack.com/pub/sflack/sflack-11.0/patches/packages/libexif-0.6.16-x86_64-1_sflack11.0.tgz

Updated package for Sflack -current:
ftp://ftp.sflack.com/pub/sflack/sflack-current/slackware/l/libexif-0.6.16-x86_64-1.tgz


MD5 signatures:
+-------------+

Sflack 11.0 package:
117467bb62d05832a7a4781a24246b4a libexif-0.6.16-x86_64-1_sflack11.0.tgz

Sflack -current package:
6740da65122e2d71fd07199d7b10532b libexif-0.6.16-x86_64-1.tgz


Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg libexif-0.6.16-x86_64-1_sflack11.0.tgz


+-----+

Sflack Linux Security Team
http://sflack.com/gpg-key
security at sflack.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFGcTKYw79R6/xskD8RAt3sAKCbEVmGn+R9U4QWoQb9jmAQTwOQDwCgj2F1
WwJiHuevLUxYMS/Aeq3rIKI=
=GVYi
-----END PGP SIGNATURE-----