-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 22 Jan 2019 20:46:50 +0100 Source: libjpeg-turbo Binary: libjpeg-dev libjpeg62-turbo-dev libjpeg62-turbo libjpeg62-turbo-dbg libturbojpeg1 libturbojpeg1-dbg libturbojpeg1-dev libjpeg-turbo-progs libjpeg-turbo-progs-dbg Architecture: source all amd64 Version: 1:1.3.1-12+deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Ondřej Surý <ondrej@debian.org> Changed-By: Mike Gabriel <sunweaver@debian.org> Description: libjpeg-dev - Development files for the JPEG library [dummy package] libjpeg-turbo-progs - Programs for manipulating JPEG files libjpeg-turbo-progs-dbg - Programs for manipulating JPEG files (debugging symbols) libjpeg62-turbo - libjpeg-turbo JPEG runtime library libjpeg62-turbo-dbg - Debugging symbols for the libjpeg-turbo JPEG library libjpeg62-turbo-dev - Development files for the libjpeg-turbo JPEG library libturbojpeg1 - TurboJPEG runtime library - SIMD optimized libturbojpeg1-dbg - TurboJPEG runtime library - SIMD optimized (debugging symbols) libturbojpeg1-dev - Development files for the TurboJPEG library Changes: libjpeg-turbo (1:1.3.1-12+deb8u1) jessie-security; urgency=medium . * Non-maintainer upload by the LTS team. * CVE-2018-11212: Check image size when reading targa file. Throw an error when image width or height is 0. * CVE-2018-11213, CVE-2018-11214: Check range of integer values in PPM text file. Add checks to ensure values are within the specified range. (This in theory also fixes unimportant-to-Debian issue CVE-2016-3616). * CVE-2018-1152: tjLoadImage(): Fix FPE triggered by malformed BMP. Checksums-Sha1: 0c3f15a72d8bab3ba61209559a97eeb082385dd7 2591 libjpeg-turbo_1.3.1-12+deb8u1.dsc 5fa19252e5ca992cfa40446a0210ceff55fbe468 1390282 libjpeg-turbo_1.3.1.orig.tar.gz 929a62fc58ada8ab6f6399d16f4c142637b3f133 81232 libjpeg-turbo_1.3.1-12+deb8u1.debian.tar.xz 3abc2e216fb8578e86c35bd56ed1bc807106e7e8 49546 libjpeg-dev_1.3.1-12+deb8u1_all.deb 21336b77bc74f3fe9527c84657573c2a6e1b3d3b 456972 libjpeg62-turbo-dev_1.3.1-12+deb8u1_amd64.deb 95ff1fe13e325b408de03a766b0049b751a7f6f0 116686 libjpeg62-turbo_1.3.1-12+deb8u1_amd64.deb 7ab160eb962654df2b6aa5f5d1bd52e5e307ffab 318686 libjpeg62-turbo-dbg_1.3.1-12+deb8u1_amd64.deb 2415e219e8e2ffc8f8916abd16294585a0746e3a 126982 libturbojpeg1_1.3.1-12+deb8u1_amd64.deb 7b1bacd158e9bdc564550a9c7dd4a45aa3c7a63b 355334 libturbojpeg1-dbg_1.3.1-12+deb8u1_amd64.deb d26bc7a7f546ae8248b328b6f79aaa2e0f730301 498016 libturbojpeg1-dev_1.3.1-12+deb8u1_amd64.deb c696a1f7b2864f9f38dcb39c571912ed30cfd3ee 83232 libjpeg-turbo-progs_1.3.1-12+deb8u1_amd64.deb 6e646b26eae093dcfe654c762d531e7ede67ccd1 187578 libjpeg-turbo-progs-dbg_1.3.1-12+deb8u1_amd64.deb Checksums-Sha256: 1e25b1182557628cc43e271a9703ac91f8029062ef848c58f57a17d20929b336 2591 libjpeg-turbo_1.3.1-12+deb8u1.dsc c132907417ddc40ed552fe53d6b91d5fecbb14a356a60ddc7ea50d6be9666fb9 1390282 libjpeg-turbo_1.3.1.orig.tar.gz 80db43c97a0c7c7f42794773261061bec5989edce52326ccd235b101edbb825e 81232 libjpeg-turbo_1.3.1-12+deb8u1.debian.tar.xz ad5144db360e9fb84eba426b0ec7841a41c2b584abf97048d45e09dddb7c1873 49546 libjpeg-dev_1.3.1-12+deb8u1_all.deb 7ec7f926e3ac443373c90805cec6ed1afb0c0d4bcc950e5e594da08cade27441 456972 libjpeg62-turbo-dev_1.3.1-12+deb8u1_amd64.deb 717cf834afa6e71b70041b301656158ad541995e32d71158ef355ce54b276c3c 116686 libjpeg62-turbo_1.3.1-12+deb8u1_amd64.deb b9838169c5abf690151ac5d57507280395ddeaa956f00a1e79db174b854dcb60 318686 libjpeg62-turbo-dbg_1.3.1-12+deb8u1_amd64.deb c4f2184f28563792da03677745d57510eed0d88118fe849bbeb31c83e07aff17 126982 libturbojpeg1_1.3.1-12+deb8u1_amd64.deb a7db947d9b39e212d9694c5b02f0a5790ab8dd50ea96b335d807960a83586e3a 355334 libturbojpeg1-dbg_1.3.1-12+deb8u1_amd64.deb 374ad1a88df74f9eaabea4efe9d518fa5bb2c65fdacf2566540e99fa69f6d126 498016 libturbojpeg1-dev_1.3.1-12+deb8u1_amd64.deb 8fd805b373e9c80a5fba61f7e57d70d94919a73779a363790903573e51566191 83232 libjpeg-turbo-progs_1.3.1-12+deb8u1_amd64.deb 17d3246b30d49b29ce47597c47c83c155cb80aa769943f90d5b1e21f38eb4305 187578 libjpeg-turbo-progs-dbg_1.3.1-12+deb8u1_amd64.deb Files: 378ec007f9461933723d6301f1841201 2591 graphics optional libjpeg-turbo_1.3.1-12+deb8u1.dsc 2c3a68129dac443a72815ff5bb374b05 1390282 graphics optional libjpeg-turbo_1.3.1.orig.tar.gz 7c680599ee7e96fd2641c6f8adb61558 81232 graphics optional libjpeg-turbo_1.3.1-12+deb8u1.debian.tar.xz d2ab54e1d253b1def0f2c34fa36dc288 49546 libdevel optional libjpeg-dev_1.3.1-12+deb8u1_all.deb 78337e6ac166e0cd20672913f2de6320 456972 libdevel optional libjpeg62-turbo-dev_1.3.1-12+deb8u1_amd64.deb a464cd08f50ad1c2055a14b068b3184c 116686 libs optional libjpeg62-turbo_1.3.1-12+deb8u1_amd64.deb 63184328927234b8969985eb3e88263a 318686 debug extra libjpeg62-turbo-dbg_1.3.1-12+deb8u1_amd64.deb 096863f3db60dc789df3fd041665e8c9 126982 libs optional libturbojpeg1_1.3.1-12+deb8u1_amd64.deb 66f55f6b8cd865def473cc482098a012 355334 debug extra libturbojpeg1-dbg_1.3.1-12+deb8u1_amd64.deb 0bd8b41d6bbfb733d52f77cfbb48385e 498016 libdevel optional libturbojpeg1-dev_1.3.1-12+deb8u1_amd64.deb 0a369f314dfd2261fd46c79a43eb2174 83232 graphics optional libjpeg-turbo-progs_1.3.1-12+deb8u1_amd64.deb 8c596c1601d962490d9580fc2351b321 187578 debug extra libjpeg-turbo-progs-dbg_1.3.1-12+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAlxHiv0VHHN1bndlYXZl ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxXYAP+JP7ZgvtheCkeR52lem1zfKxXKLJ IYcTw8vDMNQXQ6d91wg4QEZiygt+stpkcltxg4LVKI3v7clweMZiQ++ByY4a0++e PVgsVi971xKiUgZlwQb6Y/KkvVJdtX0uLR2gNAqAkBrOOR9ec7WlP/MyW0/6Vb9c 4M6kWcVs36Rma5efhRR1/kFCfFZgvm146QA+K2NmB1DC8jCKZuaqtCxK3YCRc0kg /yPwHiPtKTMd1ZIH1ZdeXJ+As76aIyy4nDiIYovYGna65wjOX1UME62ryeJyUKav ktom17DxS/BNM/sG6riiqVeIvIt4oA0I+HOSiziVds/lbXuZyXXmj0WQPFIK+xIK n5+VVC03yArXqEb+VK8o+gFCC8Bh4mdrfv4hqZSvyiI3BpuoPODhVe/IEdoOlHYF hfnHxAoEt00Z35z8htSwhIP2k1ClJpTvhBwnQDcV/3a8Yn6vjCeyzfUbg8QI9JtB eNGh10iTqqLy3nyBJZVb+bhEHPSYs4s0vDmhRW/LlmyffPGjOA4L0zkcqlQB+TlX A7OC/ZcoFvV9qjYJy1+5zoO3Cx5E76w2iR5sHwlMzugY46lB14ucKb29KbZASUI1 UEH3W4xzJs031afjMGdwBop7ZJle+MgpdnztJSFsc8vMadMxrUVQrKXCcmfHJ0rz cuksrmcYj2CBlGw= =Qifa -----END PGP SIGNATURE-----