-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 11 Sep 2019 15:30:09 +0200 Source: libonig Binary: libonig2 libonig2-dbg libonig-dev Architecture: source amd64 Version: 5.9.5-3.2+deb8u3 Distribution: jessie-security Urgency: high Maintainer: Jörg Frings-Fürst <debian@jff-webhosting.net> Changed-By: Sylvain Beucler <beuc@debian.org> Description: libonig-dev - Development files for libonig2 libonig2 - Oniguruma regular expressions library libonig2-dbg - Debugging symbols for libonig2 Changes: libonig (5.9.5-3.2+deb8u3) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Backport recursion monitoring (with a fixed limit to avoid changing the API; higher limit exhausts the default stack size) * Fix CVE-2019-16163: Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c. Checksums-Sha1: a6c9820bd35f4e59c91585b64c312067dc391df7 1559 libonig_5.9.5-3.2+deb8u3.dsc c988f0f21d5d32510210a4dcb2deb86e70465443 10636 libonig_5.9.5-3.2+deb8u3.debian.tar.xz 5aa359feda7a2008218058dbddc0cf74f3fa3c8e 117756 libonig2_5.9.5-3.2+deb8u3_amd64.deb 6552842ae347b3b589a32987c0fb680ef57e4b6f 201112 libonig2-dbg_5.9.5-3.2+deb8u3_amd64.deb c4f52811d7a91dcefb0d7e0705722fde2efb9027 79628 libonig-dev_5.9.5-3.2+deb8u3_amd64.deb Checksums-Sha256: 6d86b3a5524f08262e68e9a6fe6c8e601427b4303e53880d7a78142214e1f1f2 1559 libonig_5.9.5-3.2+deb8u3.dsc 088289008e7f63d6eb5e347277f75d04b5e6825bcf3cbb4cc758c45beb5fbd85 10636 libonig_5.9.5-3.2+deb8u3.debian.tar.xz 7e82d5b089d123dfb1eff699b9e8cca8dd41ff9665906f00cf9b38a4afada2c0 117756 libonig2_5.9.5-3.2+deb8u3_amd64.deb 8f2e792e5194aacba6f964c0b2beb7c4367f0b5224ec9b4ce6771b84d23d647f 201112 libonig2-dbg_5.9.5-3.2+deb8u3_amd64.deb 4ef1d29d6173271dd0b31d9971ea78f6c602785eb88e0451d3f722c5507e78fc 79628 libonig-dev_5.9.5-3.2+deb8u3_amd64.deb Files: 1b84a8b079991bfca75df4159a06103d 1559 libs extra libonig_5.9.5-3.2+deb8u3.dsc d98726e472bee8d4992cf0c993a2e8a0 10636 libs extra libonig_5.9.5-3.2+deb8u3.debian.tar.xz d087b8813af79582c42af9a3444ea9cb 117756 libs optional libonig2_5.9.5-3.2+deb8u3_amd64.deb d3469c4643b1c963d72838e7ccb36acc 201112 debug extra libonig2-dbg_5.9.5-3.2+deb8u3_amd64.deb 1865c23fb2a7c3d707485685190bc94e 79628 libdevel optional libonig-dev_5.9.5-3.2+deb8u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEQic8GuN/xDR88HkSj/HLbo2JBZ8FAl16Df8ACgkQj/HLbo2J BZ+bRwgAp//oHoNQVwM9RZ9YNqyzm2BWw+JPwb1CrRQFBMFz49AjEP/TgVHLe1r8 HR5+lZQSHp6KX+ga0dAMA+Tzv3/LHZ3qr4MgeFDToOBmMzo+KaSGeMBEnBiS1YiO 3QbVuFuk9JLPjZ1Ku9JAaSxQ2bHJyVJRcE6ZTn5wHHq9dErejW3aH+LIHxDOfzHW WanflHqDDQUoivS/k1HVda+JmhW9yJEBoQFDXfWIEMUAFJdDnymteWCN2n9wBFWN cpsnyb8TXQgflUI+MWLM9NDP2Nm2QgcSg1vJFZ58J+HtBaw7zReneIUQJylFWWs6 DMWhmSgW5r9aa/hdNrC5qaivMChRJw== =zQ5X -----END PGP SIGNATURE-----