-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 10 Nov 2018 18:34:46 +0100 Source: gettext Binary: gettext-base gettext gettext-el gettext-doc autopoint libgettextpo0 libasprintf0v5 libgettextpo-dev libasprintf-dev Architecture: source Version: 0.19.8.1-9 Distribution: unstable Urgency: medium Maintainer: Santiago Vila <sanvila@debian.org> Changed-By: Santiago Vila <sanvila@debian.org> Description: autopoint - The autopoint program from GNU gettext gettext - GNU Internationalization utilities gettext-base - GNU Internationalization utilities for the base system gettext-doc - Documentation for GNU gettext gettext-el - Emacs po-mode for editing gettext .po files libasprintf-dev - GNU Internationalization library development files libasprintf0v5 - GNU library to use fprintf and friends in C++ libgettextpo-dev - GNU Internationalization library development files libgettextpo0 - GNU Internationalization library Closes: 913173 Changes: gettext (0.19.8.1-9) unstable; urgency=medium . * Fix double-free problem with *.po file input. Closes: #913173. Patch extracted from upstream git where it was fixed by Daiki Ueno. For reference, this is CVE-2018-18751. * Add bison to Build-Depends, required by the above. Checksums-Sha1: a6fce80e66c025aac4102898fe53b92ae11db50a 2011 gettext_0.19.8.1-9.dsc a798fb0408739e36b09a8f93af6c630bb29d1578 32792 gettext_0.19.8.1-9.debian.tar.xz 586a7c4c807f82e0b23819d8da24fcd69ca52d95 10751 gettext_0.19.8.1-9_source.buildinfo Checksums-Sha256: 1854346197e167b6ac7eaa3cc0630cbfcad4b47c21980f045ee5c82fe37f9593 2011 gettext_0.19.8.1-9.dsc 646bee2ac7de6d6c8e64a612a03abaf9dab116671ec258199671894e90faf73e 32792 gettext_0.19.8.1-9.debian.tar.xz 1d7fa6627642a4b8cf510bccf7b9ed389246f59b5657bc4f5132ffc692d88042 10751 gettext_0.19.8.1-9_source.buildinfo Files: fefbe58f8c469eefb833d30aac4dc9be 2011 devel optional gettext_0.19.8.1-9.dsc 8e8190d1de59901c5064e4d01dc76c56 32792 devel optional gettext_0.19.8.1-9.debian.tar.xz 7234ef96b70f2c5345743f8a669249fc 10751 devel optional gettext_0.19.8.1-9_source.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEE1Uw7+v+wQt44LaXXQc5/C58bizIFAlvnFzAACgkQQc5/C58b izIJgAf9FH8FfEnKEdbDAOScxzm3Bq3gATuCjnkr7t0phMH8U5wEjVVajfNm4brB 2JRcM3kv6RTv28ATt6ADuYGcm7JodYbTthiTEwHArUqg4/kLT9mV1b9ddEWVcvq3 T6Z/iSHkg0YpYW5LsYPOvElGUxXbWYsmEidngxbFAcuFXhQ8+/KMO09yk1sJKjU/ jfQMghOxgvkON+X0488dAwL6lSwYzOyysf7dk/esZ1FC3fmS++rhPDKt+tj5dEo3 ASbB0taUS32VhWqLx71Cw0RGAbLZEgMSC/PykvJk/OV3Lbt20KqF1ujWugitjzSR VD8zOj7Vwtkwg+cczsK6SE4T/lFWaA== =mDy5 -----END PGP SIGNATURE-----