<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="6c3051a4927013b3038e41497d05506d"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="2998">
  <id>dbg111-libgdiplus0</id>
  <title>mono: libgdiplus image processing integer overflow vulnerabilities</title>
  <release>openSUSE 11.1 DEBUGINFO</release>
  <issued date="1282660682"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=630756" id="630756" title="bug number 630756" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1526" id="CVE-2010-1526" title="CVE-2010-1526" type="cve"/>
  </references>
  <description>This update fixes three integer overflows found by Secunia
Research member Stefan Cornelius that could possibly be
exploited to execute arbitrary code:
- &quot;gdip_load_tiff_image()&quot; by processing specially crafted
  TIFF images
- &quot;gdip_load_jpeg_image_internal()&quot; by processing specially
  crafted JPEG images
- &quot;gdip_read_bmp_image()&quot;by processing specially crafted
  BMP image (CVE-2010-1526)
</description>
  <pkglist>
    <collection>
        <package name="libgdiplus0-debuginfo" arch="i586" version="2.0" release="11.33.1">
          <filename>libgdiplus0-debuginfo-2.0-11.33.1.i586.rpm</filename>
        </package>
        <package name="libgdiplus0-debuginfo" arch="ppc" version="2.0" release="11.33.1">
          <filename>libgdiplus0-debuginfo-2.0-11.33.1.ppc.rpm</filename>
        </package>
        <package name="libgdiplus0-debuginfo" arch="x86_64" version="2.0" release="11.33.1">
          <filename>libgdiplus0-debuginfo-2.0-11.33.1.x86_64.rpm</filename>
        </package>
        <package name="libgdiplus0-debugsource" arch="i586" version="2.0" release="11.33.1">
          <filename>libgdiplus0-debugsource-2.0-11.33.1.i586.rpm</filename>
        </package>
        <package name="libgdiplus0-debugsource" arch="ppc" version="2.0" release="11.33.1">
          <filename>libgdiplus0-debugsource-2.0-11.33.1.ppc.rpm</filename>
        </package>
        <package name="libgdiplus0-debugsource" arch="x86_64" version="2.0" release="11.33.1">
          <filename>libgdiplus0-debugsource-2.0-11.33.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
