[CVE-2012-1175] gnash integer overflow

Related Vulnerabilities: CVE-2012-1175   CVE-2010-4337   CVE-2011-4328  

Debian Bug report logs - #664023
[CVE-2012-1175] gnash integer overflow

version graph

Reported by: Luciano Bello <luciano@debian.org>

Date: Wed, 14 Mar 2012 22:27:16 UTC

Severity: grave

Tags: patch, security

Found in version gnash/0.8.8-5

Fixed in versions gnash/0.8.10-5, gnash/0.8.8-5+squeeze1

Done: Gabriele Giacone <1o5g4r8o@gmail.com>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Information forwarded to debian-bugs-dist@lists.debian.org, Debian Flash Team <pkg-flash-devel@lists.alioth.debian.org>:
Bug#664023; Package gnash. (Wed, 14 Mar 2012 22:27:20 GMT) (full text, mbox, link).


Acknowledgement sent to Luciano Bello <luciano@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Flash Team <pkg-flash-devel@lists.alioth.debian.org>. (Wed, 14 Mar 2012 22:27:21 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Luciano Bello <luciano@debian.org>
To: submit@bugs.debian.org
Subject: [CVE-2012-1175] gnash integer overflow
Date: Wed, 14 Mar 2012 23:24:41 +0100
[Message part 1 (text/plain, inline)]
Package: gnash
Severity: grave
Tags: security patch

The following vulnerability had been reported against gnash: 
http://www.openwall.com/lists/oss-security/2012/03/14/5

The patch can be found in the report.

Please use CVE-2012-1175 for this issue and check if the stable version 
(0.8.8-5) is affected. If it's the case, can you prepare and patch for it? I can 
take care of the DSA.

Cheers,
luciano
[signature.asc (application/pgp-signature, inline)]

Reply sent to Gabriele Giacone <1o5g4r8o@gmail.com>:
You have taken responsibility. (Thu, 15 Mar 2012 04:21:04 GMT) (full text, mbox, link).


Notification sent to Luciano Bello <luciano@debian.org>:
Bug acknowledged by developer. (Thu, 15 Mar 2012 04:21:04 GMT) (full text, mbox, link).


Message #10 received at 664023-close@bugs.debian.org (full text, mbox, reply):

From: Gabriele Giacone <1o5g4r8o@gmail.com>
To: 664023-close@bugs.debian.org
Subject: Bug#664023: fixed in gnash 0.8.10-5
Date: Thu, 15 Mar 2012 04:17:57 +0000
Source: gnash
Source-Version: 0.8.10-5

We believe that the bug you reported is fixed in the latest version of
gnash, which is due to be installed in the Debian FTP archive:

browser-plugin-gnash_0.8.10-5_amd64.deb
  to main/g/gnash/browser-plugin-gnash_0.8.10-5_amd64.deb
gnash-common-opengl_0.8.10-5_all.deb
  to main/g/gnash/gnash-common-opengl_0.8.10-5_all.deb
gnash-common_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-common_0.8.10-5_amd64.deb
gnash-cygnal_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-cygnal_0.8.10-5_amd64.deb
gnash-dbg_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-dbg_0.8.10-5_amd64.deb
gnash-dev_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-dev_0.8.10-5_amd64.deb
gnash-doc_0.8.10-5_all.deb
  to main/g/gnash/gnash-doc_0.8.10-5_all.deb
gnash-ext-fileio_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-ext-fileio_0.8.10-5_amd64.deb
gnash-ext-lirc_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-ext-lirc_0.8.10-5_amd64.deb
gnash-ext-mysql_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-ext-mysql_0.8.10-5_amd64.deb
gnash-opengl_0.8.10-5_all.deb
  to main/g/gnash/gnash-opengl_0.8.10-5_all.deb
gnash-tools_0.8.10-5_amd64.deb
  to main/g/gnash/gnash-tools_0.8.10-5_amd64.deb
gnash_0.8.10-5.debian.tar.gz
  to main/g/gnash/gnash_0.8.10-5.debian.tar.gz
gnash_0.8.10-5.dsc
  to main/g/gnash/gnash_0.8.10-5.dsc
gnash_0.8.10-5_amd64.deb
  to main/g/gnash/gnash_0.8.10-5_amd64.deb
klash-opengl_0.8.10-5_all.deb
  to main/g/gnash/klash-opengl_0.8.10-5_all.deb
klash_0.8.10-5_amd64.deb
  to main/g/gnash/klash_0.8.10-5_amd64.deb
konqueror-plugin-gnash_0.8.10-5_amd64.deb
  to main/g/gnash/konqueror-plugin-gnash_0.8.10-5_amd64.deb
mozilla-plugin-gnash_0.8.10-5_all.deb
  to main/g/gnash/mozilla-plugin-gnash_0.8.10-5_all.deb
python-gtk-gnash_0.8.10-5_amd64.deb
  to main/g/gnash/python-gtk-gnash_0.8.10-5_amd64.deb
swfdec-gnome_0.8.10-5_all.deb
  to main/g/gnash/swfdec-gnome_0.8.10-5_all.deb
swfdec-mozilla_0.8.10-5_all.deb
  to main/g/gnash/swfdec-mozilla_0.8.10-5_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 664023@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Gabriele Giacone <1o5g4r8o@gmail.com> (supplier of updated gnash package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 15 Mar 2012 03:04:37 +0100
Source: gnash
Binary: gnash-common gnash klash gnash-tools gnash-cygnal browser-plugin-gnash konqueror-plugin-gnash python-gtk-gnash gnash-ext-fileio gnash-ext-mysql gnash-ext-lirc gnash-dev gnash-dbg gnash-doc gnash-common-opengl gnash-opengl klash-opengl swfdec-mozilla swfdec-gnome mozilla-plugin-gnash
Architecture: source amd64 all
Version: 0.8.10-5
Distribution: unstable
Urgency: low
Maintainer: Debian Flash Team <pkg-flash-devel@lists.alioth.debian.org>
Changed-By: Gabriele Giacone <1o5g4r8o@gmail.com>
Description: 
 browser-plugin-gnash - GNU Shockwave Flash (SWF) player - Plugin for Mozilla and derivat
 gnash      - GNU Shockwave Flash (SWF) player
 gnash-common - GNU Shockwave Flash (SWF) player - Common files/libraries
 gnash-common-opengl - dummy package for gnash-common-opengl removal
 gnash-cygnal - GNU Shockwave Flash (SWF) player - Media server
 gnash-dbg  - GNU Shockwave Flash (SWF) player - Debug symbols
 gnash-dev  - GNU Shockwave Flash (SWF) player - Development files
 gnash-doc  - GNU Shockwave Flash (SWF) player - API documentation
 gnash-ext-fileio - GNU Shockwave Flash (SWF) player - Fileio extension
 gnash-ext-lirc - GNU Shockwave Flash (SWF) player - LIRC extension
 gnash-ext-mysql - GNU Shockwave Flash (SWF) player - MySQL extension
 gnash-opengl - dummy package for gnash-opengl removal
 gnash-tools - GNU Shockwave Flash (SWF) player - Command-line Tools
 klash      - GNU Shockwave Flash (SWF) player - Standalone player for KDE
 klash-opengl - dummy package for klash-opengl removal
 konqueror-plugin-gnash - GNU Shockwave Flash (SWF) player - Plugin for Konqueror
 mozilla-plugin-gnash - dummy package for renaming to browser-plugin-gnash
 python-gtk-gnash - GNU Shockwave Flash (SWF) player - Python bindings
 swfdec-gnome - dummy package for transition to Gnash
 swfdec-mozilla - dummy package for transition to browser-plugin-gnash
Closes: 664023
Changes: 
 gnash (0.8.10-5) unstable; urgency=low
 .
   * Fix CVE-2012-1175 (Closes: #664023).
Checksums-Sha1: 
 91df36cfc71f8e412b7a19a9a6e8a5bd27634a2f 3210 gnash_0.8.10-5.dsc
 13516033495a39690b87e575a3e853f8791c4f48 35499 gnash_0.8.10-5.debian.tar.gz
 af4b5453d6300ba2f956180adf0800d363a5b74a 2794282 gnash-common_0.8.10-5_amd64.deb
 7e420639f25527abaaf32111876a069da28919c8 233364 gnash_0.8.10-5_amd64.deb
 a26d80f20735ae4e79a83c6178c0b13b2347835f 225766 klash_0.8.10-5_amd64.deb
 9880a591abfd01e9f6d790c0b1bbc4f7ec5781b4 178184 gnash-tools_0.8.10-5_amd64.deb
 df3eae16dcf97963e4564ac46d392d7315598aa3 744886 gnash-cygnal_0.8.10-5_amd64.deb
 2e79f5d1ee038a9b1c50a0ccb804def0d420d674 142318 browser-plugin-gnash_0.8.10-5_amd64.deb
 e8a1bebf5d9fe3794259b1e895ea4d5ee7e62b06 57000 konqueror-plugin-gnash_0.8.10-5_amd64.deb
 7269324d71693d5d3b8c315acd419cef784ca4a1 97146 python-gtk-gnash_0.8.10-5_amd64.deb
 86ee3d56b6e074c3f2fbca44d03f034ddadd6400 68960 gnash-ext-fileio_0.8.10-5_amd64.deb
 20fb2e18d8a428192d75d3e2c6c1b08a61d88266 72152 gnash-ext-mysql_0.8.10-5_amd64.deb
 ce455c964da45af10cda5c7ae8ffc94a5fa19a2b 62758 gnash-ext-lirc_0.8.10-5_amd64.deb
 adfcc7d60e53aa9e67835c4bf34f2d3b17750724 261548 gnash-dev_0.8.10-5_amd64.deb
 c638a1442411e3681da413e1780e326815bc7e16 63246656 gnash-dbg_0.8.10-5_amd64.deb
 6d102b02fe0636efe9b0ec8e9db83733eb96d710 5131730 gnash-doc_0.8.10-5_all.deb
 be7e4cda0c933fd8929f41e36478e06a47abb63c 27106 gnash-common-opengl_0.8.10-5_all.deb
 98a4ea2cdace90e4b5c89f9191b57d5741dae93c 27098 gnash-opengl_0.8.10-5_all.deb
 0ddb7668a9303e1cdfd7d3845f9b63ced41649aa 27100 klash-opengl_0.8.10-5_all.deb
 1c4ef95779b73a565767d90cc2e50b52755301fd 27122 swfdec-mozilla_0.8.10-5_all.deb
 cfa314f5466a56eb15a53a537257cb43155c6f1b 27106 mozilla-plugin-gnash_0.8.10-5_all.deb
 d3f4c0d34868c5f7d28ead60062136434df037bc 27114 swfdec-gnome_0.8.10-5_all.deb
Checksums-Sha256: 
 cbc3153c9877e25cbafc62b08aac16820372f096830a3adff7b901079ca28605 3210 gnash_0.8.10-5.dsc
 e092daa62bac5c874b6a008a2c296554dffbe58b98efa5b30b1cf47e490e9e96 35499 gnash_0.8.10-5.debian.tar.gz
 403a3cbc6e57347fb6bd46c270e4fc36d39832973c8abb3f00c51634bb751ed2 2794282 gnash-common_0.8.10-5_amd64.deb
 279889592981fc17b53aab8654df8e4fe7d0ea0f961071a173aeb6e588dfb143 233364 gnash_0.8.10-5_amd64.deb
 95b177c975448f7eb22cf4033b8f7873918a4100856b0771eeda61ec9a314675 225766 klash_0.8.10-5_amd64.deb
 d1fc0eae96f42f95aeb418ce459bcef26223fef695057798130b02199d2c27e0 178184 gnash-tools_0.8.10-5_amd64.deb
 4c242ec49058d3da763f465e6de31b03a2b3a6ba7b67e738c36c4b81ae39bf61 744886 gnash-cygnal_0.8.10-5_amd64.deb
 3a49a0de90bdbcce5d85481f04fd989adf37170241e1c7fdbf07bc34ef715304 142318 browser-plugin-gnash_0.8.10-5_amd64.deb
 76b0f09e79c9d5013acd0d6e9f6ba16009f4ac7393d16709637139f768c7518c 57000 konqueror-plugin-gnash_0.8.10-5_amd64.deb
 4ec6090814760c20442db1615ec39cd1cb4bf6816641c6934148838ca6d888e8 97146 python-gtk-gnash_0.8.10-5_amd64.deb
 636e9c1fd8ed1c0f870a46a3843f1a2d02d634fd9a99724631b4ae81c985435d 68960 gnash-ext-fileio_0.8.10-5_amd64.deb
 6920b98852ad062a67b2688667569d9e1a2006c7dc4cdc9d2ae47c3ff97e695c 72152 gnash-ext-mysql_0.8.10-5_amd64.deb
 ecb10cf23d5a5db1ef6adef07a8537e1c4b3f71807ba5cfd048309aa1fe61d81 62758 gnash-ext-lirc_0.8.10-5_amd64.deb
 0625920f1482c58fa3b363818610d8c3bbd5562d8ef203d04623b7c78c117d13 261548 gnash-dev_0.8.10-5_amd64.deb
 5e32d7b9205e7a64637d571d4b73032794e77160ff41023995f1c358b05a32b8 63246656 gnash-dbg_0.8.10-5_amd64.deb
 9e70a0443eec517d51d2d3e903c64497bb24a359bf3fcff8c5800629f591d719 5131730 gnash-doc_0.8.10-5_all.deb
 0126c89074d59aef741598c0fe28426b1b9f7e369cd2d78eb7e850674aefcbfd 27106 gnash-common-opengl_0.8.10-5_all.deb
 fe93a328aad1d9680fddc90d854c45c0a9d5cfdafa6597d7e93dd52f658a9e12 27098 gnash-opengl_0.8.10-5_all.deb
 56d3c7b1635d416c5c7adc5c02fc0fc55fffe1ffebae3a3c7a3ea09dc174f511 27100 klash-opengl_0.8.10-5_all.deb
 f1c35eea8d4a9daf75aba0913add72ef74c3ea0e3e1289a1f5bca7a4bfc2d6ee 27122 swfdec-mozilla_0.8.10-5_all.deb
 501dc20f66e51fc6b10e5e340619612c44b6cc77c62910012611715ea03e9d7a 27106 mozilla-plugin-gnash_0.8.10-5_all.deb
 afb2f08e46b2a3d64db985ad5f6ea270aa8aab7bfd4ec8c8f51d93bec9c3095b 27114 swfdec-gnome_0.8.10-5_all.deb
Files: 
 df0ac3f885ae0ab195f3a55ac9fbf6f3 3210 video optional gnash_0.8.10-5.dsc
 3953682331973d0731311bfdefee5624 35499 video optional gnash_0.8.10-5.debian.tar.gz
 27765ada92a11b5eceebf2fc9d93df03 2794282 video optional gnash-common_0.8.10-5_amd64.deb
 b75c02176ba93ce0c5490ce447cef6df 233364 video optional gnash_0.8.10-5_amd64.deb
 e8dadca8f04faecf715dcebf422a7a40 225766 video optional klash_0.8.10-5_amd64.deb
 d3deedb65566f4f01f323517e86bf876 178184 video optional gnash-tools_0.8.10-5_amd64.deb
 75ee7f5b9ee26cfea1d48ee4f1b66897 744886 video optional gnash-cygnal_0.8.10-5_amd64.deb
 bb0a79cf6fc03ab5f8438cd2ee5a66b8 142318 video optional browser-plugin-gnash_0.8.10-5_amd64.deb
 cc0138cc5ea8524ae1fc419adfcbae81 57000 video optional konqueror-plugin-gnash_0.8.10-5_amd64.deb
 36b0cda50a82f9ac7116f0b90a9db6f0 97146 python optional python-gtk-gnash_0.8.10-5_amd64.deb
 3f00ed3b0236784b8e80a877cb89900c 68960 video optional gnash-ext-fileio_0.8.10-5_amd64.deb
 dbc977b3509f2a012609b130706fd982 72152 video optional gnash-ext-mysql_0.8.10-5_amd64.deb
 e8d1634ecbeb8cb5d6faef9462e9991e 62758 video optional gnash-ext-lirc_0.8.10-5_amd64.deb
 10114e3ff253cb4d7394f79348351783 261548 libdevel optional gnash-dev_0.8.10-5_amd64.deb
 3e8c1b58a86fcd1febb31a1e283d7877 63246656 debug extra gnash-dbg_0.8.10-5_amd64.deb
 77554b3e65abf428eba69e59a75bab24 5131730 doc optional gnash-doc_0.8.10-5_all.deb
 8f33d90423737366a27334fd33518d57 27106 oldlibs extra gnash-common-opengl_0.8.10-5_all.deb
 7cfea63ef93e6a68b9e6f696f1256e21 27098 oldlibs extra gnash-opengl_0.8.10-5_all.deb
 f76fe20a7ae37ef94a4b6920757a5952 27100 oldlibs extra klash-opengl_0.8.10-5_all.deb
 297fffac180107a745db6b4fbd5902cb 27122 oldlibs extra swfdec-mozilla_0.8.10-5_all.deb
 9999d107ac82df34bd06e40d1c22914c 27106 oldlibs extra mozilla-plugin-gnash_0.8.10-5_all.deb
 33f10a419786ae64e9385c698b3a5dd1 27114 oldlibs extra swfdec-gnome_0.8.10-5_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAk9hZH8ACgkQp3cdCbVcnCuviACeIY+mQrjh+VM14bjUY688dAsu
XNgAoIUJrd4WEbsg7aW8Sq2WnToYk9bu
=HuxS
-----END PGP SIGNATURE-----





Marked as found in versions gnash/0.8.8-5. Request was from Didier Raboud <odyx@debian.org> to control@bugs.debian.org. (Thu, 15 Mar 2012 15:09:05 GMT) (full text, mbox, link).


Reply sent to Gabriele Giacone <1o5g4r8o@gmail.com>:
You have taken responsibility. (Tue, 20 Mar 2012 21:36:43 GMT) (full text, mbox, link).


Notification sent to Luciano Bello <luciano@debian.org>:
Bug acknowledged by developer. (Tue, 20 Mar 2012 21:36:44 GMT) (full text, mbox, link).


Message #17 received at 664023-close@bugs.debian.org (full text, mbox, reply):

From: Gabriele Giacone <1o5g4r8o@gmail.com>
To: 664023-close@bugs.debian.org
Subject: Bug#664023: fixed in gnash 0.8.8-5+squeeze1
Date: Tue, 20 Mar 2012 21:32:16 +0000
Source: gnash
Source-Version: 0.8.8-5+squeeze1

We believe that the bug you reported is fixed in the latest version of
gnash, which is due to be installed in the Debian FTP archive:

browser-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/browser-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
gnash-common-opengl_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/gnash-common-opengl_0.8.8-5+squeeze1_amd64.deb
gnash-common_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/gnash-common_0.8.8-5+squeeze1_amd64.deb
gnash-cygnal_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/gnash-cygnal_0.8.8-5+squeeze1_amd64.deb
gnash-dbg_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/gnash-dbg_0.8.8-5+squeeze1_amd64.deb
gnash-doc_0.8.8-5+squeeze1_all.deb
  to main/g/gnash/gnash-doc_0.8.8-5+squeeze1_all.deb
gnash-opengl_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/gnash-opengl_0.8.8-5+squeeze1_amd64.deb
gnash-tools_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/gnash-tools_0.8.8-5+squeeze1_amd64.deb
gnash_0.8.8-5+squeeze1.debian.tar.gz
  to main/g/gnash/gnash_0.8.8-5+squeeze1.debian.tar.gz
gnash_0.8.8-5+squeeze1.dsc
  to main/g/gnash/gnash_0.8.8-5+squeeze1.dsc
gnash_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/gnash_0.8.8-5+squeeze1_amd64.deb
klash-opengl_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/klash-opengl_0.8.8-5+squeeze1_amd64.deb
klash_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/klash_0.8.8-5+squeeze1_amd64.deb
konqueror-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/konqueror-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
mozilla-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/mozilla-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
swfdec-gnome_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/swfdec-gnome_0.8.8-5+squeeze1_amd64.deb
swfdec-mozilla_0.8.8-5+squeeze1_amd64.deb
  to main/g/gnash/swfdec-mozilla_0.8.8-5+squeeze1_amd64.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 664023@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Gabriele Giacone <1o5g4r8o@gmail.com> (supplier of updated gnash package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 15 Mar 2012 08:51:14 +0000
Source: gnash
Binary: gnash-common gnash klash gnash-tools gnash-cygnal browser-plugin-gnash konqueror-plugin-gnash gnash-dbg gnash-doc gnash-common-opengl gnash-opengl klash-opengl swfdec-mozilla swfdec-gnome mozilla-plugin-gnash
Architecture: source all amd64
Version: 0.8.8-5+squeeze1
Distribution: stable-security
Urgency: high
Maintainer: Debian Flash Team <pkg-flash-devel@lists.alioth.debian.org>
Changed-By: Gabriele Giacone <1o5g4r8o@gmail.com>
Description: 
 browser-plugin-gnash - GNU Shockwave Flash (SWF) player - Plugin for Mozilla and derivat
 gnash      - GNU Shockwave Flash (SWF) player
 gnash-common - GNU Shockwave Flash (SWF) player - Common files/libraries
 gnash-common-opengl - dummy package for gnash-common-opengl removal
 gnash-cygnal - GNU Shockwave Flash (SWF) player - Media server
 gnash-dbg  - GNU Shockwave Flash (SWF) player - Debug symbols
 gnash-doc  - GNU Shockwave Flash (SWF) player - API documentation
 gnash-opengl - dummy package for gnash-opengl removal
 gnash-tools - GNU Shockwave Flash (SWF) player - Command-line Tools
 klash      - GNU Shockwave Flash (SWF) player - Standalone player for KDE
 klash-opengl - dummy package for klash-opengl removal
 konqueror-plugin-gnash - GNU Shockwave Flash (SWF) player - Plugin for Konqueror
 mozilla-plugin-gnash - dummy package for renaming to browser-plugin-gnash
 swfdec-gnome - dummy package for transition to gnash
 swfdec-mozilla - dummy package for transition to browser-plugin-gnash
Closes: 605419 649384 664023
Changes: 
 gnash (0.8.8-5+squeeze1) stable-security; urgency=high
 .
   * Fix CVE-2012-1175 (Closes: #664023).
   * Fix CVE-2010-4337 (Closes: #605419).
   * Fix CVE-2011-4328 (Closes: #649384).
     + Add libboost-iostreams-dev as B-D.
Checksums-Sha1: 
 7632e517de3029053742978aaf32fcbd89a2d3ff 2362 gnash_0.8.8-5+squeeze1.dsc
 0643f95693022b9fe6c574799f3e90e0d0eb6655 5074764 gnash_0.8.8.orig.tar.gz
 845a615c75fd8d4f9763f91a68bf99ddbb4cd3cc 42342 gnash_0.8.8-5+squeeze1.debian.tar.gz
 3cd6a9d4343c7e1cb8c977c4e2339bd0c86b5d2c 5703642 gnash-doc_0.8.8-5+squeeze1_all.deb
 3dd9e93d7af693ddf352bdf4f6a59578b8a6ca9a 2786880 gnash-common_0.8.8-5+squeeze1_amd64.deb
 7060922685a1486857f55771fafb2a53b294f88d 181534 gnash_0.8.8-5+squeeze1_amd64.deb
 f81360534b88c47fd9a8b039df2c0047db5b6adb 181526 klash_0.8.8-5+squeeze1_amd64.deb
 5cbc962f8800b7ff8d54f4951e4ae835e9e9511d 160236 gnash-tools_0.8.8-5+squeeze1_amd64.deb
 d6cabd5f875a2b117129b36e8defa73dbd45adfb 160074 gnash-cygnal_0.8.8-5+squeeze1_amd64.deb
 9df288276f81db44be5882e18a037f3eddb51b2e 142164 browser-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 752068ba6f7db7d3807c697376d0f766ce8cf0ce 55170 konqueror-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 af757e874ff14a69bcc1cb059696c86fdf562c7b 31481204 gnash-dbg_0.8.8-5+squeeze1_amd64.deb
 0022280e26df929a74791d076c3abce0d9269911 24834 gnash-common-opengl_0.8.8-5+squeeze1_amd64.deb
 764e5981fbd4e32fdde743c80253faa2abc0409b 24832 gnash-opengl_0.8.8-5+squeeze1_amd64.deb
 69c4d5342fc91c279e5273cc5bc4cd427e5a4be3 24830 klash-opengl_0.8.8-5+squeeze1_amd64.deb
 3e01507acac0803415d86cfa57102dd0519ee0b9 24856 swfdec-mozilla_0.8.8-5+squeeze1_amd64.deb
 e4a10616fc961b2ce8f4bcf26fd924e219f2f812 24832 mozilla-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 530d5d8e248904144374891a1232b6dafdce1aed 24838 swfdec-gnome_0.8.8-5+squeeze1_amd64.deb
Checksums-Sha256: 
 d7a1088e9c613f186620f8b9f88621f7f5ace70d01e841a7d9e90486acf1afb7 2362 gnash_0.8.8-5+squeeze1.dsc
 3f19ddf1d18ba28ad949fb4eb3468786cd28abb59154a68a002551ee4e67f5e4 5074764 gnash_0.8.8.orig.tar.gz
 bb1cfa4e3ddfe1a4a92becc2f890d2c827d82746e86045b556ea9bbfab8d0786 42342 gnash_0.8.8-5+squeeze1.debian.tar.gz
 6c62bb20211d01179bab18864632c88d6e370ca2f39707ad3c08cf7f3df162f3 5703642 gnash-doc_0.8.8-5+squeeze1_all.deb
 560170aa8b2a18bf99fe8fa6b864d82b47665c9b36536e6c75f441742155273f 2786880 gnash-common_0.8.8-5+squeeze1_amd64.deb
 4fc56fc9c4e0e2088df6e50d041326be8d9b265dc684a007ee4a404fff55019a 181534 gnash_0.8.8-5+squeeze1_amd64.deb
 e3bccb5ca0b6ff5ea32ab6c8f52f0658407130d856e0db3a443b633671bbf3af 181526 klash_0.8.8-5+squeeze1_amd64.deb
 88bdc5b566c53a5ba0426bf3fa6c0773403f3401914384e12e53a555556dcb1b 160236 gnash-tools_0.8.8-5+squeeze1_amd64.deb
 f6983c60058f8913a9e9a4df38ef94dadc147ef8dd19822ced8991c305b87cea 160074 gnash-cygnal_0.8.8-5+squeeze1_amd64.deb
 39f11742108c91788a1abcbdcb6fa8927b62bda5a3c2b098a842a4ed2f4738f6 142164 browser-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 0a659b3160c690f65c9e146a8734d323145f5999b30c501b39c63e33c2de0ca3 55170 konqueror-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 d797615e36ff9195f3b0b16d3428dbda731f242d7f7e13e1e7a3937bbb28ea6a 31481204 gnash-dbg_0.8.8-5+squeeze1_amd64.deb
 6edb169d809dbbe25d6f43a43fdc88ee06528a642112202d38b0f380af9b5407 24834 gnash-common-opengl_0.8.8-5+squeeze1_amd64.deb
 e824821631f26ef94e826bcb7e747d77699ca943fdaa1cbabbe65e2ced0f372e 24832 gnash-opengl_0.8.8-5+squeeze1_amd64.deb
 8873fb764f36544e5f5508c9233d3bc4d811b225d483f2892a579c6609d1737b 24830 klash-opengl_0.8.8-5+squeeze1_amd64.deb
 b654fe44e6d900a7fe1e9ec65fecfcfc019c234d8f9903d1742f039191aae206 24856 swfdec-mozilla_0.8.8-5+squeeze1_amd64.deb
 44c20d18c335400e3066e10c9a188a474bea5594ae768c9faeef309946b5d336 24832 mozilla-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 6c8b9cb38a3616168cbd0af67e6ac81eed57f02a9b7a1a13e1ccf1d1289d8b5b 24838 swfdec-gnome_0.8.8-5+squeeze1_amd64.deb
Files: 
 845b72a3bea29e2934d476dc5a593aae 2362 video optional gnash_0.8.8-5+squeeze1.dsc
 aec414ee3bebb8901054818fae735214 5074764 video optional gnash_0.8.8.orig.tar.gz
 e83e0b5314a9413c52bd08074e9683f9 42342 video optional gnash_0.8.8-5+squeeze1.debian.tar.gz
 559e08de360962df5eb8a327084a07e4 5703642 doc optional gnash-doc_0.8.8-5+squeeze1_all.deb
 7e1cf9562d9c41b9b7a89f3186a5aeb5 2786880 video optional gnash-common_0.8.8-5+squeeze1_amd64.deb
 1e2a82a1e0aa3a0adaf543e4cfeb2747 181534 video optional gnash_0.8.8-5+squeeze1_amd64.deb
 234296bc660f4f80627c84c517b6d6a9 181526 video optional klash_0.8.8-5+squeeze1_amd64.deb
 a8fb1ecf800e51cd67ea0336b60be2a8 160236 video optional gnash-tools_0.8.8-5+squeeze1_amd64.deb
 9f0a57441a7164753585982e4641c90a 160074 video optional gnash-cygnal_0.8.8-5+squeeze1_amd64.deb
 632169dc99fb41df4970d5809bed6762 142164 video optional browser-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 df7f15d9988bee8009713e5c9fa709e0 55170 video optional konqueror-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 e511523aaa90cc04cfac51224cec109e 31481204 debug extra gnash-dbg_0.8.8-5+squeeze1_amd64.deb
 2ab519de203ded364fddc41ce60c58c2 24834 video extra gnash-common-opengl_0.8.8-5+squeeze1_amd64.deb
 ae632b63ac4f44bc8214a3a22c2ca804 24832 video extra gnash-opengl_0.8.8-5+squeeze1_amd64.deb
 811101dd859f0af75e76f79d735a8ec9 24830 video extra klash-opengl_0.8.8-5+squeeze1_amd64.deb
 1839d66d664fb84f54dc8e79f2922cec 24856 video extra swfdec-mozilla_0.8.8-5+squeeze1_amd64.deb
 d78e0ffd2a90a060b72905e0f2b3e7bd 24832 video extra mozilla-plugin-gnash_0.8.8-5+squeeze1_amd64.deb
 6e931c9e6c256cb30f2bf1e3356acee2 24838 video extra swfdec-gnome_0.8.8-5+squeeze1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk9j968ACgkQQWTRs4lLtHk8qQCdHRyv5Jga7RMa7ZbDddIBqwBl
2vUAnjv0pxfLwHLGs1baNUuJ1uBT9gde
=rLpn
-----END PGP SIGNATURE-----





Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Thu, 17 May 2012 07:36:05 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 17:02:51 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.