-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 02 Nov 2019 19:16:19 +0100 Source: ncurses Architecture: source Version: 6.1+20181013-2+deb10u2 Distribution: buster Urgency: medium Maintainer: Craig Small <csmall@debian.org> Changed-By: Sven Joachim <svenjoac@gmx.de> Closes: 942401 Changes: ncurses (6.1+20181013-2+deb10u2) buster; urgency=medium . * Cherry-pick tic fixes from upstream patchlevels 20191012, 20191015 and 20191019 (Closes: #942401). - Check for invalid hashcode in _nc_find_type_entry and nc_find_entry (CVE-2019-17594). - Check for missing character after backslash in fmt_entry (CVE-2019-17595). - Check for acsc with odd length in dump_entry in check for one-one mapping. - Check for missing character after backslash in write_it. - Modify tic to exit if it cannot remove a conflicting name, because treating that as a partial success can cause an infinite loop in use-resolution. Checksums-Sha1: ed7904b940476997b7fefa844f5bd917eec14ece 4179 ncurses_6.1+20181013-2+deb10u2.dsc 2f6d909f968686b2cd51ddd899fe2c4a6f898bda 61664 ncurses_6.1+20181013-2+deb10u2.debian.tar.xz 2ac80702e01a33dc92babc7982fda3f9004bb7ba 5633 ncurses_6.1+20181013-2+deb10u2_source.buildinfo Checksums-Sha256: 8318631ff3298951a93d6dd6c20bd47c9e5fdaaf30578d541bd6404bdd5317ea 4179 ncurses_6.1+20181013-2+deb10u2.dsc 4574ec11ce2577e76f30f8d40cc2a9ebf94d8208f47247021da88b7b09e77df9 61664 ncurses_6.1+20181013-2+deb10u2.debian.tar.xz 4a1a288a94105e741273602640584d005137ae8ff8750efe1af03c9561c54f9c 5633 ncurses_6.1+20181013-2+deb10u2_source.buildinfo Files: 98b8b2b7ab90f586868ad80c4c5f8daa 4179 libs required ncurses_6.1+20181013-2+deb10u2.dsc 3f10bbd22130474b1719151f030a997d 61664 libs required ncurses_6.1+20181013-2+deb10u2.debian.tar.xz fab24601fb35f8f6ab384f5114b4defa 5633 libs required ncurses_6.1+20181013-2+deb10u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKF8heKgv5Jai5p4QOxBucY1rMawFAl29yOcACgkQOxBucY1r Max8Mw/8Dd/XowXSpNPEd4fcv4dyAq9ro6/gVyUgXKhM3xeiSjp1QRiWPZYCvxmt ZPhl1ds6FGCmmvRd5ivG7cdNekTySYQ2v7Z79R8Kg+GKvuBcrFytCEDDHYI945bW F+Sj7YqNpU3S9p9fQ79B1Zd6UOd5Cfsmc+u39PXNxGEI72TGYhblskJtUKU3c84p wB63r3u23+OjUmAr3NKAXiLkpxdbvVv64qhQng1T7aANHNpK87xSS/pWhFddIt7a wkHNGi1uUg1UDn3LcT5TwZUznK8kOrFi271i1mSjE5jT69hnjouc1LC3Tn/2mime clBSw5a0xawyD7QaU7xuFUC+oGrT+UTyE3jqy1zZZLhTQkpY9ek3Wd1hZ7Q6elE1 6p17cm2iWGT+r3S+rtDl7AHW1R5QXACMt7KcnCNWARlFlZUK5VkgaL+A5oclsJgN 6Xv1ePtiXm0C5undGmnaZgpkJzCpfNw1msrgfeZ/xB8cIq6xdltkjNhNYNjhEFJq +Ikthhv8ujT016iv3hlXcGHL91S5g0YtL7LUwRADedITmb3T++76Zs6wUyT2LxbT vJpX7JJrYI+jdImiJI4BvvM1A5X8KpXqtAx+Gn+A4aTZaKZv8Y9ESgSt9f4vRAeZ 3/CdfmK+9FKK2wtLRQSvNyC8Qzow7AA3kM2mnvo1x+I+njp3C3M= =SU/Z -----END PGP SIGNATURE-----