-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 26 Sep 2019 19:13:02 +0200 Source: poppler Binary: libpoppler46 libpoppler-dev libpoppler-private-dev libpoppler-glib8 libpoppler-glib-dev libpoppler-glib-doc gir1.2-poppler-0.18 libpoppler-qt4-4 libpoppler-qt4-dev libpoppler-qt5-1 libpoppler-qt5-dev libpoppler-cpp0 libpoppler-cpp-dev poppler-utils poppler-dbg Architecture: source amd64 all Version: 0.26.5-2+deb8u11 Distribution: jessie-security Urgency: medium Maintainer: Loic Minier <lool@dooz.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: gir1.2-poppler-0.18 - GObject introspection data for poppler-glib libpoppler-cpp-dev - PDF rendering library -- development files (CPP interface) libpoppler-cpp0 - PDF rendering library (CPP shared library) libpoppler-dev - PDF rendering library -- development files libpoppler-glib-dev - PDF rendering library -- development files (GLib interface) libpoppler-glib-doc - PDF rendering library -- documentation for the GLib interface libpoppler-glib8 - PDF rendering library (GLib-based shared library) libpoppler-private-dev - PDF rendering library -- private development files libpoppler-qt4-4 - PDF rendering library (Qt 4 based shared library) libpoppler-qt4-dev - PDF rendering library -- development files (Qt 4 interface) libpoppler-qt5-1 - PDF rendering library (Qt 5 based shared library) libpoppler-qt5-dev - PDF rendering library -- development files (Qt 5 interface) libpoppler46 - PDF rendering library poppler-dbg - PDF rendering library -- debugging symbols poppler-utils - PDF utilities (based on Poppler) Changes: poppler (0.26.5-2+deb8u11) jessie-security; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2019-12493 stack-based buffer over-read because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions * CVE-2018-21009 integer overflow in Parser::makeStream in Parser.cc * CVE-2018-20650 denial of service due to the lack of a check for the dict data type Checksums-Sha1: 9155a17eb9fe8a7e43141e40533fff6dd5338c44 3465 poppler_0.26.5-2+deb8u11.dsc 12937666faee80bae397a8338a3357e864d77d53 1595232 poppler_0.26.5.orig.tar.xz 05b77095ee2fe0d819a0dee3b6dd267c18c3f98c 47584 poppler_0.26.5-2+deb8u11.debian.tar.xz 6be77790a8ed91ae629d557eb29a981301d37d3b 1213966 libpoppler46_0.26.5-2+deb8u11_amd64.deb 0f07ff8700ec7c8d3ebf9162e0ecb5bc0d360986 768402 libpoppler-dev_0.26.5-2+deb8u11_amd64.deb 87dd3b5dbc4198651a0b83e4444dc9c8ab500f91 181534 libpoppler-private-dev_0.26.5-2+deb8u11_amd64.deb c111f3314a4879e870020b6b46d4d45f48c7c9aa 122676 libpoppler-glib8_0.26.5-2+deb8u11_amd64.deb 7e8517b0514b1eaae8814a0d15f3b398aa1656b8 164584 libpoppler-glib-dev_0.26.5-2+deb8u11_amd64.deb f2d6056a6f8b2285fa4431d2a7f0fb8357fd9752 86762 libpoppler-glib-doc_0.26.5-2+deb8u11_all.deb a979aa07959e7f6f02bd99db90fb0be8a450dc44 35264 gir1.2-poppler-0.18_0.26.5-2+deb8u11_amd64.deb 89156edc3b832d732ccb07c4eca20a281a5d6063 128756 libpoppler-qt4-4_0.26.5-2+deb8u11_amd64.deb 8dc0050856caab3c3a58774498adec553e3ee3cb 159692 libpoppler-qt4-dev_0.26.5-2+deb8u11_amd64.deb cceaf9e00b8feda9f7a8f69d6d22ac222030d876 132966 libpoppler-qt5-1_0.26.5-2+deb8u11_amd64.deb 4ba352f2525c1c7e7c0a7facc22ae2c7e8364b8d 166438 libpoppler-qt5-dev_0.26.5-2+deb8u11_amd64.deb c8284f829eba99fddf84ac2e7ac609f2f1662a40 45768 libpoppler-cpp0_0.26.5-2+deb8u11_amd64.deb fc560e84ac008add0aa176a469257ae585ec8688 50252 libpoppler-cpp-dev_0.26.5-2+deb8u11_amd64.deb f1f1bbc914aa734657a901146f39ac5eed338d33 141910 poppler-utils_0.26.5-2+deb8u11_amd64.deb 478a4d92d2b4d492333173a4a3290b01b2c5ec05 7684854 poppler-dbg_0.26.5-2+deb8u11_amd64.deb Checksums-Sha256: 3ba446c14cea36932a8b18953bc4a247f40958dd599a78aa0e4767be794377cc 3465 poppler_0.26.5-2+deb8u11.dsc de7de5fa337431e5d1f372e8577b3707322f1dbc1dc28a70f2927476f134d1ee 1595232 poppler_0.26.5.orig.tar.xz e690a293978249f8c5dfe880605caca2b9a7e551679ef8a2221184f0305ae04e 47584 poppler_0.26.5-2+deb8u11.debian.tar.xz 42537ca68efb23fe56c71d19e6ce32a5f71292ade52a327979c557164b2b2959 1213966 libpoppler46_0.26.5-2+deb8u11_amd64.deb 8e23092eeebe020b5befd670ae1542a8e5619f7959a380b8fc58eccacdefba18 768402 libpoppler-dev_0.26.5-2+deb8u11_amd64.deb f22858cd358cb009795e6e40eaf1c3d4a6f158410a10a91e748f730e90e0d10b 181534 libpoppler-private-dev_0.26.5-2+deb8u11_amd64.deb 6ec9dc85b7fe944fe306b42637c79912d89e501231851bc284d9f519e8a28fe6 122676 libpoppler-glib8_0.26.5-2+deb8u11_amd64.deb 9751b3fbc4940dbeb952fc332016e1edae588483f1dd0773f3edcc09c340ff28 164584 libpoppler-glib-dev_0.26.5-2+deb8u11_amd64.deb db73bc41d4906a09e0604cc586c1630f269afd4b523211a84b6229208ec60eb6 86762 libpoppler-glib-doc_0.26.5-2+deb8u11_all.deb 24776b844965dca9bc76c1e559734cdc65e78357ca6ba7fa701fe37aa4df2205 35264 gir1.2-poppler-0.18_0.26.5-2+deb8u11_amd64.deb bb0d2f0859452e2092ec255d3bb2a859baea3e817edb6c4b98097c07ef549984 128756 libpoppler-qt4-4_0.26.5-2+deb8u11_amd64.deb cd0b6d0f662a57d9f04c3ce6424bfa1404bcd3467b2d602cb1cf9e3560055ccb 159692 libpoppler-qt4-dev_0.26.5-2+deb8u11_amd64.deb d8dbe6756ee73c2fda0737822227a71f135e6138e96213068631b7922d0b461d 132966 libpoppler-qt5-1_0.26.5-2+deb8u11_amd64.deb 88f24ecb6ebe715f8efefd4751664fe9dc06feadfd491a202caa5befff7be341 166438 libpoppler-qt5-dev_0.26.5-2+deb8u11_amd64.deb b2cc00525ea4d271f4cc82c3a109359bd1bc68aa4327ed8bef7d0738e599b5cb 45768 libpoppler-cpp0_0.26.5-2+deb8u11_amd64.deb 0f80b784fbe0130c45262c6b25fbf0aa3016e14c7a26a89640087ca2cdb7a707 50252 libpoppler-cpp-dev_0.26.5-2+deb8u11_amd64.deb 447d11ed06dd502c7feb3d1b8620921b7ca4edb5c838b3fef502f9a92aeaf3cc 141910 poppler-utils_0.26.5-2+deb8u11_amd64.deb 91e0487b9f3ab40fe24f59919831757de3d9d29b56c9df6ba98f6706c470643d 7684854 poppler-dbg_0.26.5-2+deb8u11_amd64.deb Files: c6e276cbbed0e18baf6cf53f0be9bcc9 3465 devel optional poppler_0.26.5-2+deb8u11.dsc 786c943eee550e3a977c181e7778b1c8 1595232 devel optional poppler_0.26.5.orig.tar.xz 4849a6a09589e304496d2e8dbcbb894d 47584 devel optional poppler_0.26.5-2+deb8u11.debian.tar.xz ebb744267724e9de7b0435243b94fbf1 1213966 libs optional libpoppler46_0.26.5-2+deb8u11_amd64.deb e6b9788e2f7c7aa19bf5011c79f258ad 768402 libdevel optional libpoppler-dev_0.26.5-2+deb8u11_amd64.deb a181240f4dbefc11080663ccc1253fc7 181534 libdevel optional libpoppler-private-dev_0.26.5-2+deb8u11_amd64.deb eece29e994f9879e92c1d4dcaf9b95ae 122676 libs optional libpoppler-glib8_0.26.5-2+deb8u11_amd64.deb b7e297ddddef78dbdfbf32aca7852a0d 164584 libdevel optional libpoppler-glib-dev_0.26.5-2+deb8u11_amd64.deb 9d092cab6eb37fdc837373b53e3108b1 86762 doc optional libpoppler-glib-doc_0.26.5-2+deb8u11_all.deb 594b22b5a7d693c7001397547c290100 35264 introspection optional gir1.2-poppler-0.18_0.26.5-2+deb8u11_amd64.deb 8386b234c2c9c685fac79728a7401488 128756 libs optional libpoppler-qt4-4_0.26.5-2+deb8u11_amd64.deb 09194bdfc7eb932edaf6a34ff155d34c 159692 libdevel optional libpoppler-qt4-dev_0.26.5-2+deb8u11_amd64.deb 7159048204a475bd4d75c124fbddb6e0 132966 libs optional libpoppler-qt5-1_0.26.5-2+deb8u11_amd64.deb f1f310da16eca74bc9588582fec0c4e8 166438 libdevel optional libpoppler-qt5-dev_0.26.5-2+deb8u11_amd64.deb 154c9b80c8a8614347ae90a8ac50111c 45768 libs optional libpoppler-cpp0_0.26.5-2+deb8u11_amd64.deb 92bfcd837e706bee2865f628c999d436 50252 libdevel optional libpoppler-cpp-dev_0.26.5-2+deb8u11_amd64.deb 445dbd16fe23517d4e0618b391c560c7 141910 utils optional poppler-utils_0.26.5-2+deb8u11_amd64.deb a0e0f7a9e91a6802f489e678583a28ac 7684854 debug extra poppler-dbg_0.26.5-2+deb8u11_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl2SSQJfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYRyZ3EADAfV4lx2a1HQ5YJYxiGdjaZvtG186I EgQJW9Zv/ZgrKKewZOC/JwUmofHnAs176WeQM/H9zX68Pv+GXNKerrCs0yopW3ri 7F979OzRhOZkljObyIzrtGB+kDQNfoh9x5NmQtHAAEF6V5yYu6tO70g2zdiLwQSC 37OObTrNWbJHes6BCD6sJfXZplmx8WE3xkoSQNSFpciox4wWRtafBw/TmKvJoR8P YJQbv3/ZB2iS4UaXMOJsxdjbIPY5zgp8P33snqb9q/useX7kMCTUqStV1r0fNfpB kY9Q5RkV5yrmNxGE8HDZHn/DkVTLxHkLEjrRW/nN66Y2wFFHxrFwLuSiqV4iU7r2 BL1wK8bUaMwxXC8UMKrYgMZCV2yiu/FGe3rNWjLgSwB5PAEiMPV61NRzQXkqGgIn R9HAXhDEDcClSvcfR5Rjx5kQgQl+DHZfYEXABX/AONdvCvY9LAFCepLeziVhtGnP R8M0e8SrSfAggZIhlUo3CDoN7BeooFkrHlQTP2UMwplLGKyQBaD4abJPztNUGDrW 8TJo87MaxZQE7MVCZzRAcsZDNGAZcuY/3wVvDvUjzUq6zk0zu7LoiwntFQP9djIH 6P3R3RTdBrcBuAxBuweRpxwH/gYs1JKV27zHrT9mQry8s4T7xu5SLdwpdo0xGeMx BO+7cM90ek9oZg== =bZMV -----END PGP SIGNATURE-----