-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 19 Oct 2019 19:06:33 +0200 Source: aspell Binary: aspell aspell-doc libaspell15 libaspell-dev libpspell-dev Architecture: source all amd64 Version: 0.60.7~20110707-1.3+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Brian Nelson <pyro@debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: aspell - GNU Aspell spell-checker aspell-doc - Documentation for GNU Aspell spell-checker libaspell-dev - Development files for applications with GNU Aspell support libaspell15 - GNU Aspell spell-checker runtime library libpspell-dev - Development files for applications with pspell support Changes: aspell (0.60.7~20110707-1.3+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2019-17544: It was discovered that Aspell incorrectly handled certain inputs which leads to a stack-based buffer over-read. An attacker could potentially access sensitive information. Checksums-Sha1: 86721b3c61d310edcf58db802f6cb73b2810a8ef 2393 aspell_0.60.7~20110707-1.3+deb8u1.dsc b5a41b92d70740efe7785baaefe1616c69c34637 1876992 aspell_0.60.7~20110707.orig.tar.gz 4ff3698e10196836c038d71fe7026da89c5b0e17 121868 aspell_0.60.7~20110707-1.3+deb8u1.debian.tar.xz cc49243eee50a539203903c818581fea12d00ba8 260720 aspell-doc_0.60.7~20110707-1.3+deb8u1_all.deb 0dd8fc63c66fbf5c5052f48283a1c4e2237c74ab 229856 aspell_0.60.7~20110707-1.3+deb8u1_amd64.deb 034cf6c4241ac3239c40b8ef880640b0e4af756a 358532 libaspell15_0.60.7~20110707-1.3+deb8u1_amd64.deb 39b9df4769603c1703f1f6be2f01ff730ba18b67 40052 libaspell-dev_0.60.7~20110707-1.3+deb8u1_amd64.deb ea27ecee7c476be874688fdcfe4e62ee1685972f 37156 libpspell-dev_0.60.7~20110707-1.3+deb8u1_amd64.deb Checksums-Sha256: e690806db82932021292dbe25185e1d49f1d8993c7e5fd71d14898cbf3738d9c 2393 aspell_0.60.7~20110707-1.3+deb8u1.dsc 71a41224e224af08a0051a9048fc0b4a912acee997d4870cfd68bd7327c45b61 1876992 aspell_0.60.7~20110707.orig.tar.gz 0e7073dd5a460dc49175941836373f9e8eeb7f3b2e7fca9b7986f2278b904500 121868 aspell_0.60.7~20110707-1.3+deb8u1.debian.tar.xz a2742110ea724f474a702f8343430dee17aa04a8b6abb879443dcf1ed86e707f 260720 aspell-doc_0.60.7~20110707-1.3+deb8u1_all.deb 4c1659856dd0b3f08ce6a40544fea9f381924e60e98e31d2953870c254edd78e 229856 aspell_0.60.7~20110707-1.3+deb8u1_amd64.deb 261a45e8ea433eb3d2e2006cc0d7e121e70c44fba86ac90157532bcd39c11650 358532 libaspell15_0.60.7~20110707-1.3+deb8u1_amd64.deb c4026de784e5c7c4e5a6da8bbd4e0b96de94f7447cdf589dd79d4957249ba642 40052 libaspell-dev_0.60.7~20110707-1.3+deb8u1_amd64.deb 7551835b73a115d3322f651c0860fc1e67ec9ce539d3f958f886d242ae442114 37156 libpspell-dev_0.60.7~20110707-1.3+deb8u1_amd64.deb Files: 0e14f8448aba48c61cf98e016f9e5ea8 2393 text optional aspell_0.60.7~20110707-1.3+deb8u1.dsc 9a80faddad3222b88c544e93d2ab9579 1876992 text optional aspell_0.60.7~20110707.orig.tar.gz 8839c1c349fa97a4acf627401debf5f0 121868 text optional aspell_0.60.7~20110707-1.3+deb8u1.debian.tar.xz a076cdab1b090972fdd21ccf917e8c07 260720 doc optional aspell-doc_0.60.7~20110707-1.3+deb8u1_all.deb 53dd4e49ba937c6b0e67a00d6537df8b 229856 text optional aspell_0.60.7~20110707-1.3+deb8u1_amd64.deb 76b22211789c1fca02a56e3cfe4bd370 358532 libs optional libaspell15_0.60.7~20110707-1.3+deb8u1_amd64.deb 634ddc4dd0bf75008b94f73192d6a8fa 40052 libdevel optional libaspell-dev_0.60.7~20110707-1.3+deb8u1_amd64.deb 579aa398a6d49cb8073ce5a9d4ca735a 37156 libdevel optional libpspell-dev_0.60.7~20110707-1.3+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl2rSZ5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hkw2MP/1rY6wsjfqpJx2AdHHgGwTaqIjUonLK2zsNg BU1ZdvyBdPqWr23OUYHMyHbSgLe5548OeQNoW4aSSwlH+KhbdeHz8+MB4fKKxi0d aL/TIBi6JoeexcySNG+yBhDlmUATqEYBpK9kbyXNetxeC00FAo5YSblCXmlob4xc 9ZbJ+wP4cfiNnDPliXaAS823vUu6EHgls5nRFjvlzC53ZpQM7EnH4vWvQzk8EK6o 6J0zrqo1JOaWu3WwVrN3MK3ewPpSTURYB1wiZBPVP0wnynVGkKCGAGEW5nd4FEsF xtZBu2Fn04nq3+rt8WplqdtaBWddV054+Gr/78JR0KBDUKdZhUtzDmPo9YIiheYb 6nmxJ+AKpg3fHniXauunp+diaJQTrDPRXK+UZaWE7qC31nzjVpafEqDpJqw/QNKc NSbO7IUgAxaMdSjC4dcz2p4AygO7ZTGhnQRBt25Yp2bFO780tuyzW2z6HSeQvZ6O 6srMjNfePkDNMQIgCI7n2YAtwk/XmzOJzzGX/cHg/PCoO/tZSGA/p29RLTLEWCU1 lLOVbVNTGQeAKbJ4Xb9319f1+WFNRIzd0Zj8fEATCvwjOuENpfbceo6glixNeiCk 4J3Did/7ezpv15s9dsRUf23jRJcoOtP/dkcyeOmTkJfQ/msbqbODUrqAV+imeEbp 0/MSadnT =M/KM -----END PGP SIGNATURE-----