Subject: CVS commit: pkgsrc/x11/gtk2
To: None <pkgsrc-changes@NetBSD.org>
From: Lubomir Sedlacik <salo@netbsd.org>
List: pkgsrc-changes
Date: 04/01/2005 10:51:51
Module Name:	pkgsrc
Committed By:	salo
Date:		Fri Apr  1 10:51:51 UTC 2005

Modified Files:
	pkgsrc/x11/gtk2: Makefile buildlink3.mk distinfo
Added Files:
	pkgsrc/x11/gtk2/patches: patch-ai

Log Message:
Security fix for CAN-2005-0891:

"David Costanzo has reported a vulnerability in GTK+, which can be
 exploited by malicious people to crash certain applications on
 a user's system.

 The vulnerability is caused due to a double free error in the BMP
 loader.  This can be exploited to crash an application linked against
 GTK+ when a specially crafted BMP image is processed."

Bump PKGREVISION.  Patch from Fedora.


To generate a diff of this commit:
cvs rdiff -r1.78 -r1.79 pkgsrc/x11/gtk2/Makefile
cvs rdiff -r1.16 -r1.17 pkgsrc/x11/gtk2/buildlink3.mk
cvs rdiff -r1.42 -r1.43 pkgsrc/x11/gtk2/distinfo
cvs rdiff -r0 -r1.7 pkgsrc/x11/gtk2/patches/patch-ai

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.