-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 18 Jul 2019 16:36:58 -0300 Source: exiv2 Binary: exiv2 libexiv2-13 libexiv2-dev libexiv2-doc libexiv2-dbg Architecture: source amd64 all Version: 0.24-4.1+deb8u4 Distribution: jessie-security Urgency: high Maintainer: Debian KDE Extras Team <pkg-kde-extras@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: exiv2 - EXIF/IPTC metadata manipulation tool libexiv2-13 - EXIF/IPTC metadata manipulation library libexiv2-dbg - EXIF/IPTC metadata manipulation library - debug libexiv2-dev - EXIF/IPTC metadata manipulation library - development files libexiv2-doc - EXIF/IPTC metadata manipulation library - HTML documentation Changes: exiv2 (0.24-4.1+deb8u4) jessie-security; urgency=high . * CVE-2019-13504: Prevent an integer overflow vulnerability that could result in a denial of service via a specially-crafted file. Checksums-Sha1: 795709b70d2daf40ec04e7f956b054cae4a0d088 2295 exiv2_0.24-4.1+deb8u4.dsc 2f19538e54f8c21c180fa96d17677b7cff7dc1bb 4635028 exiv2_0.24.orig.tar.gz 445862891ea6693be40c8ccb565cb3f3f71357b4 21116 exiv2_0.24-4.1+deb8u4.debian.tar.xz e21df289a1b57f68a1f45e7c229a789d3cf787a9 95002 exiv2_0.24-4.1+deb8u4_amd64.deb 54d85182cb93fcd8b24f514ba387e0af76efc488 731474 libexiv2-13_0.24-4.1+deb8u4_amd64.deb 9124f193809428b7de257dc25b8e2ba7a79fdf69 1109806 libexiv2-dev_0.24-4.1+deb8u4_amd64.deb ffbcafb22f43d1c347a3fd1668ae550fcd067c86 19109934 libexiv2-doc_0.24-4.1+deb8u4_all.deb 7f0e273af7749db30d7e50045086ae03fcc8162b 5529938 libexiv2-dbg_0.24-4.1+deb8u4_amd64.deb Checksums-Sha256: 73db57cc0dbbec67c12773d9963906d90e05ae9e5c78cf7cec98057c02d07d66 2295 exiv2_0.24-4.1+deb8u4.dsc f4a443e6c7fb9d9f5e787732f76969a64c72c4c04af69b10ed57f949c2dfef8e 4635028 exiv2_0.24.orig.tar.gz 024534cd3ed6c67bbceb5d3e3d4f8d0bb312a617c3c88119e52252d417043b5d 21116 exiv2_0.24-4.1+deb8u4.debian.tar.xz 7e719b5120c746937051f090f3459ff41387e80fd4692f4dd5f16d150e9bcd60 95002 exiv2_0.24-4.1+deb8u4_amd64.deb fa10487330c88362ccf7a34b28a346159056df120130a6136044bf456fd4a685 731474 libexiv2-13_0.24-4.1+deb8u4_amd64.deb 291965f74790087b955ca9768917ba2cb0e66c2959572708504164a71514a284 1109806 libexiv2-dev_0.24-4.1+deb8u4_amd64.deb 9acce0be6299deae5ca8d2f32728975a38588cd6c09f11d9f1c89a000a3fcd0d 19109934 libexiv2-doc_0.24-4.1+deb8u4_all.deb 784b79f0f96fb3e8be8aa6080c305b89c8b9976ea8bb0baad704200bc918fa57 5529938 libexiv2-dbg_0.24-4.1+deb8u4_amd64.deb Files: 0a1c977c9d49be62d694ef3d3fae8187 2295 graphics optional exiv2_0.24-4.1+deb8u4.dsc b8a23dc56a98ede85c00718a97a8d6fc 4635028 graphics optional exiv2_0.24.orig.tar.gz d38bc7c2c39c31bc61665062e383784d 21116 graphics optional exiv2_0.24-4.1+deb8u4.debian.tar.xz 8c0ed52e04b3fdf7e647a9bd04c1492d 95002 graphics optional exiv2_0.24-4.1+deb8u4_amd64.deb 8b25ab9e3f8edeb7c4ea696e349dae8c 731474 libs optional libexiv2-13_0.24-4.1+deb8u4_amd64.deb d1910b318383df6c4e2d7caba8ae389b 1109806 libdevel optional libexiv2-dev_0.24-4.1+deb8u4_amd64.deb 5f2b9b5726e698f446c7dfc520cd5e94 19109934 doc optional libexiv2-doc_0.24-4.1+deb8u4_all.deb 14ea7a51ed1c58888f98350440e365ad 5529938 debug extra libexiv2-dbg_0.24-4.1+deb8u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl0xzlsACgkQHpU+J9Qx Hlj1Qg/7BTwau5QLvIIctZbDQgqtSeCcekfzXYKZ995nls7kdql4LpfLDi0DxDXX UP22CqSbtTAJYT751yDhE603lwbw44eiA7oiFqSu80ONYOFyHJqcGI56aeV8Vt2e suBhYdOWWCX85yInGPf0nCICbUIstgR5SvsuwD0q+Bg7E1DDxovbpg8sC4C84ag7 jGylQlNQoLNgwPaShZ3kQtDwlULulL6cUj9x/tvKIXe8yvTXWRTmpsuuX5J5zCGb Fpa6jJ0osOqbxeuRn0nMgQuLPfSHxWH/qMXZiPtyJKBgbmtJyWfXZBU6GJ/VSi7E AjhVqHURfTlmzGGx1HxshNBn+NZkG+9oT1RWu+PkVcjr9dQlHqxu1S/GSvxbyzl4 E/+gA4vg8JGMSFMQqNZy/qA+L5JfJ0BgYSwKrwqNC7NDXivrBCU+ThyUQuzAXqBg a2g2Ka01PmaEDdnfTjYfVcfvIzvLKwpXgyDEvIdaTa1wVfy3DlrfVph6hKlXt9ik MKCIwi1RR5Zchisakw5bvSvcI8TqhZFWGkYOygPwAaqLQpI+f8I7Sehp/OsIvo8B NwR5g0/gLAe0/qGrswBCSfoZWIxr6WiqHyxHy7bYjiLpu0mthbXnFn5sgQRLYA84 v5xldkSlRUMjR6kwpkfOFG4vtWnqdCnxN5OEBD3WNAsVCwSywG8= =pWqF -----END PGP SIGNATURE-----