-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 13 Aug 2019 12:04:27 +0200 Source: evince Binary: evince evince-dbg evince-gtk evince-common libevdocument3-4 libevview3-3 libevince-dev gir1.2-evince-3.0 Architecture: source all amd64 Version: 3.14.1-2+deb8u3 Distribution: jessie-security Urgency: medium Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Emilio Pozuelo Monfort <pochu@debian.org> Description: evince - Document (PostScript, PDF) viewer evince-common - Document (PostScript, PDF) viewer - common files evince-dbg - Document (PostScript, PDF) viewer - debugging symbols evince-gtk - Document (PostScript, PDF) viewer (GTK+ version) gir1.2-evince-3.0 - GObject introspection data for the evince libraries libevdocument3-4 - Document (PostScript, PDF) rendering library libevince-dev - Document (PostScript, PDF) rendering library - development files libevview3-3 - Document (PostScript, PDF) rendering library - Gtk+ widgets Changes: evince (3.14.1-2+deb8u3) jessie-security; urgency=medium . * CVE-2017-1000159: command injection via filename when printing from DVI to PDF. * CVE-2019-1010006: integer overflow in tiff backend. * CVE-2019-11459: unhandled errors in tiff backend can lead to uninitialized memory use. * 0001-check-for-failed-rendering-jobs.patch: fix null pointer dereference if a redering job fails. Checksums-Sha1: 76f062e9700cffacd38e0391f9c7029d32d1124e 3191 evince_3.14.1-2+deb8u3.dsc 42760595375825343bdfb1e025a270c53d60537f 3082612 evince_3.14.1.orig.tar.xz d43bd7d749dc797a95d0fd140031f33ee15c5bb8 29276 evince_3.14.1-2+deb8u3.debian.tar.xz 61ad545b70cc94c9a7352377765b43c07f3a1f8d 2183344 evince-common_3.14.1-2+deb8u3_all.deb 879b6613f81a2b7dc7907aeaec536736a54d0eec 741934 evince_3.14.1-2+deb8u3_amd64.deb bc4019bd32f6a9d629db901652b0713cf6a4ba4a 1700694 evince-dbg_3.14.1-2+deb8u3_amd64.deb 0cf12cf4593cadbd5a445249abb6a60e2d0a9d25 737748 evince-gtk_3.14.1-2+deb8u3_amd64.deb d18dfdcdf9f17b18c6483dc76aa23be7419d79a5 774098 libevdocument3-4_3.14.1-2+deb8u3_amd64.deb f345112775bd4bc10b7ff015c6d5f258200898d0 708788 libevview3-3_3.14.1-2+deb8u3_amd64.deb d1698b858a60561bf27832bf6bb771b3b576cc09 868868 libevince-dev_3.14.1-2+deb8u3_amd64.deb a96d3a8382348d34e21653ee145908df8a8b30a0 617080 gir1.2-evince-3.0_3.14.1-2+deb8u3_amd64.deb Checksums-Sha256: c869bbba238ea78222b705c85e114c280c22605585a61a7276a6d4c3e900f496 3191 evince_3.14.1-2+deb8u3.dsc 13ec728d6957aa18ba21a3a66504dd52b8607596337f30f0908b62b5fcc14507 3082612 evince_3.14.1.orig.tar.xz 5e38d43c5d77fa3756451d90a63742bd6e392c549f02c2323c34607fe609e8dd 29276 evince_3.14.1-2+deb8u3.debian.tar.xz afb1738b3bda479a7e1591fd851dd91bd90705488e64e6364f2346a01db5f32e 2183344 evince-common_3.14.1-2+deb8u3_all.deb 52e72a3fdec54845433c300f167f40a555f5a418c10600ee416a23ef0514324e 741934 evince_3.14.1-2+deb8u3_amd64.deb 905bfb0fba5909181d3829d15e6b236dd52289d194a6585ed9efabf5476d4bfd 1700694 evince-dbg_3.14.1-2+deb8u3_amd64.deb 9fc714ccb1a1e0d084bf2e5aa1a6998c73d9e35ff4dc4853def124c98d0974e8 737748 evince-gtk_3.14.1-2+deb8u3_amd64.deb 66b3002cf3d1623c570d482f99c80afd1ef4b8a112f1f9874c69445fbd4bbfda 774098 libevdocument3-4_3.14.1-2+deb8u3_amd64.deb 5822ca06fffb42906011f6b100deae10392d528fda502e5f241cebd18c35d1e5 708788 libevview3-3_3.14.1-2+deb8u3_amd64.deb d141a72e0cab394436f3b96beaf8a6e1f58da0faf0863a2bfdc70fe8316162da 868868 libevince-dev_3.14.1-2+deb8u3_amd64.deb e995db89dd8eb72a7e9b51b5624a9858701c3f7d315cfc286469e4777a2188e8 617080 gir1.2-evince-3.0_3.14.1-2+deb8u3_amd64.deb Files: 801235cefdbdabd267c2f50854f706e3 3191 gnome optional evince_3.14.1-2+deb8u3.dsc 20575f13ce1a0bf31f085d2430848c40 3082612 gnome optional evince_3.14.1.orig.tar.xz 7b6f6a4985971ef855e16aa59dd4aa3e 29276 gnome optional evince_3.14.1-2+deb8u3.debian.tar.xz 99660b6ffbd496f0683ec27a0e70967c 2183344 gnome optional evince-common_3.14.1-2+deb8u3_all.deb a329d65c22f61f2c343ea668d035262d 741934 gnome optional evince_3.14.1-2+deb8u3_amd64.deb b7af1c3a11eabbf5df6df232572a8e4f 1700694 debug extra evince-dbg_3.14.1-2+deb8u3_amd64.deb 168ad1aa9cbd06dde6c973fbbfd17b40 737748 x11 optional evince-gtk_3.14.1-2+deb8u3_amd64.deb 33b8c111ab848fc10cc339acc6d1ef69 774098 libs optional libevdocument3-4_3.14.1-2+deb8u3_amd64.deb d11aa8ff4803a101ba4d9cfa9e48347f 708788 libs optional libevview3-3_3.14.1-2+deb8u3_amd64.deb ea14f512803534861d395287d683f2c6 868868 libdevel optional libevince-dev_3.14.1-2+deb8u3_amd64.deb d2c24f40655b878fd8094e75bd822fd1 617080 introspection optional gir1.2-evince-3.0_3.14.1-2+deb8u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl1SnHYACgkQnUbEiOQ2 gwIbpRAAu/cMGB82/si5FFtJ4CAEvOP5NJHPoV4CUuKk/MhSTSoIL1cVqv6mYVT9 FtZnJEj3QVmfhr5zU5QFlFhbmNbtLjh9s1DlEZDHPLOEhGd7uNx6tM840mLenlXN PTrQ32v0reE5NPe5RYFEyRIjEElzSWpAYcr/lCGrXEbmMLGvkDd0qvgwD8VdAzLt YWBW9tbDqofoZdlZt2BsYLPkD/2Q+FBGUak+mYgOYCpoO6ta2mvQ59jTNudP6WDD nDKhuVNRTfuftYJdH/GeJtA40iGNoPXBtW6H2FPYgDXHGIGBZk5uo86IgRue3/Qu 5JZe5t6iPbsfcZMekrBAlO5389ixnr88pAcWtVPE7YzDOKN/uPhAtpUvE0T2jCDD jM8EkplQ4H4Uhx174T8X6GH9IW2v5WXxqlBeiXP9xCqc1NL2YgD60If+ihQ83P/c N3t1gK6AiL5mvY5X6nwZIiaoHeFGZOrbohi+0hmeLFLROrbLbnUCt2U6ZNUpexyc HyLudwTGoZf0t5w0sSEr0e2UPT5B98Gfx21sGL4U3YyNgdSaFX+1Wh+u0rvf7yU+ akZcO2PfuGsphnAm9SecYWfAl1lW8L9tgLW10dc2e4Npd3pku2KZLww0bfXB+WeP KisjEn7b1wCJlzdGNadXqoLIQrJRK7MvJtdmxUG3YMq9AnTmhbE= =9jsO -----END PGP SIGNATURE-----