freebsd-ports/print/ghostscript8
Hiroki Sato 6fefb478d6 Fix multiple integer overflows and lack of boundary check found
and marked as CVE-2009-583 and CVE-2009-584:

CVE-2009-583:

  Multiple integer overflows in icc.c in the International Color
  Consortium (ICC) Format library (aka icclib), as used in
  Ghostscript 8.64 and earlier and Argyll Color Management
  System (CMS) 1.0.3 and earlier, allow context-dependent
  attackers to cause a denial of service (heap-based buffer
  overflow and application crash) or possibly execute arbitrary
  code by using a device file for a translation request that
  operates on a crafted image file and targets a certain "native
  color space," related to an ICC profile in a (1) PostScript
  or (2) PDF file with embedded images.

CVE-2009-584:

  icc.c in the International Color Consortium (ICC) Format
  library (aka icclib), as used in Ghostscript 8.64 and earlier
  and Argyll Color Management System (CMS) 1.0.3 and earlier,
  allows context-dependent attackers to cause a denial of
  service (application crash) or possibly execute arbitrary code
  by using a device file for processing a crafted image file
  associated with large integer values for certain sizes, related
  to an ICC profile in a (1) PostScript or (2) PDF file with
  embedded images.

Security:	CVE-2009-583
Security:	CVE-2009-584
Approved by:	portmgr (pav)
2009-04-20 08:08:50 +00:00
..
files Fix multiple integer overflows and lack of boundary check found 2009-04-20 08:08:50 +00:00
distinfo Update to 8.64. Changes include: 2009-03-28 20:05:52 +00:00
Makefile Fix multiple integer overflows and lack of boundary check found 2009-04-20 08:08:50 +00:00
Makefile.drivers - Fix typos in OPTIONS. 2008-06-20 18:12:06 +00:00
pkg-descr The following repocopies have been done for print/ghostscript-* 2008-06-01 08:51:52 +00:00
pkg-plist Update to 8.64. Changes include: 2009-03-28 20:05:52 +00:00