Subject: CVS commit: pkgsrc/graphics/dia
From: Lubomir Sedlacik
Date: 2006-04-04 16:52:15
Message id: 20060404145215.666A62DA27@cvs.netbsd.org

Log Message:
Security fix for CVE-2006-1550:

"Multiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87
 and later before 0.95-pre6 allow user-complicit attackers to have an unknown
 impact via a crafted xfig file, possibly involving an invalid (1) color index,
 (2) number of points, or (3) depth."

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1550
http://mail.gnome.org/archives/dia-list/2006-March/msg00149.html

Fix from Dia CVS.

Files:
RevisionActionfile
1.42modifypkgsrc/graphics/dia/Makefile
1.15modifypkgsrc/graphics/dia/distinfo
1.1addpkgsrc/graphics/dia/patches/patch-ac
1.1addpkgsrc/graphics/dia/patches/patch-ad