From: Hans U. N. <gp...@n-...> - 2005-03-08 23:49:18
|
Hi, I've just stumbled upon Ubuntu Security Notice USN-91-1 March 07, 2005 libexif vulnerabilities https://bugzilla.ubuntulinux.org/7152=20 and as I can't remember having read anything about this issue here, I am writing this mail. This notice appears to address a problem in libexif 0.6.9, and the code in dispute has been rewritten since. Therefore, I am not sure whether our current code is still vulnerable or not. Further references for the people with code knowledge to read through: http://www.ubuntulinux.org/support/documentation/usn/usn-91-1 https://bugzilla.ubuntulinux.org/show_bug.cgi?id=3D7152 https://bugzilla.ubuntu.com/attachment.cgi?id=3D1508 (I don't know the code. I just help to build the beast :-) Gru=C3=9F, Uli |