Pullup ticket 1320 - requested by salo
authorsnj <snj>
Thu, 6 Apr 2006 00:37:04 +0000 (00:37 +0000)
committersnj <snj>
Thu, 6 Apr 2006 00:37:04 +0000 (00:37 +0000)
commita031d21b7d5b51f7d8a7dd2ad28483cbab73856c
treee87ac854c81181969231d95e99d13e23eabf3e50
parent7dee30c0ae0d9986ce8cf061479027b76c1f1c8c
Pullup ticket 1320 - requested by salo
security fix for dia

Revisions pulled up:
- pkgsrc/graphics/dia/Makefile 1.42
- pkgsrc/graphics/dia/distinfo 1.15
- pkgsrc/graphics/dia/patches/patch-ac 1.1
- pkgsrc/graphics/dia/patches/patch-ad 1.1

   Module Name:    pkgsrc
   Committed By:   salo
   Date:           Tue Apr  4 14:52:15 UTC 2006

   Modified Files:
           pkgsrc/graphics/dia: Makefile distinfo
   Added Files:
           pkgsrc/graphics/dia/patches: patch-ac patch-ad

   Log Message:
   Security fix for CVE-2006-1550:

   "Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia
    0.87 and later before 0.95-pre6 allow user-complicit attackers to have an
    unknown impact via a crafted xfig file, possibly involving an invalid (1)
    color index, (2) number of points, or (3) depth."

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1550
   http://mail.gnome.org/archives/dia-list/2006-March/msg00149.html

   Fix from Dia CVS.
graphics/dia/Makefile
graphics/dia/distinfo
graphics/dia/patches/patch-ac
graphics/dia/patches/patch-ad