ChangeLog for: 2016-06-16 22:52:57
l/gd-2.2.1-x86_64-1.txz: Upgraded.
This update fixes the following security issues:
Stack consumption vulnerability allows remote attackers to cause a denial of
service via a crafted imagefilltoborder call.
Integer signedness error allows remote attackers to cause a denial of service
or potentially execute arbitrary code via crafted compressed gd2 data, which
triggers a heap-based buffer overflow.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8874
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3074
(* Security fix *)
n/php-5.6.22-x86_64-2.txz: Rebuilt.
Added option --with-vpx-dir=/usr. Thanks to Pierre ANDREENKO.