Changelog
eglibc (2.13-38+deb7u9) wheezy; urgency=medium
[ Aurelien Jarno ]
* patches/any/cvs-CVE-2015-1781.diff: new patch from upstream to fix
a buffer overflow in getanswer_r (CVE-2015-1781). Closes: #796105.
* patches/any/cvs-fnmatch-overflow.diff: new patch from upstream to fix
a buffer overflow (read past end of buffer) in internal_fnmatch.
* patches/any/cvs-_IO_wstr_overflow.diff: new patch from upstream to fix
an integer overlow in IO_wstr_overflow.
* patches/any/cvs-CVE-2014-8121.diff: new patch from upstream to fix
an unexpected closing of nss_files databases after lookups, causing
denial of service (CVE-2014-8121). Closes: #779587.
* patches/any/cvs-ld_pointer_guard.diff: new patch from upstream to
unconditionally disable LD_POINTER_GUARD. Closes: #798316, #801691.
[ Raphaël Hertzog ]
* debian/patches/any/cvs-strxfrm-buffer-overflows.diff: new patch
from upstream to fix memory allocations issues that can lead to buffer
overflows on the stack. Closes: #803927.
-- Aurelien Jarno <email address hidden> Mon, 21 Dec 2015 00:01:08 +0100