-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 06 Sep 2019 16:11:01 +0900 Source: libsixel Binary: libsixel-dev libsixel1 libsixel-bin Architecture: source Version: 1.5.2-2+deb9u1 Distribution: stretch Urgency: medium Maintainer: NOKUBI Takatsugu <knok@daionet.gr.jp> Changed-By: NOKUBI Takatsugu <knok@daionet.gr.jp> Description: libsixel-bin - DEC SIXEL graphics codec implementation (binary) libsixel-dev - DEC SIXEL graphics codec implementation (develop) libsixel1 - DEC SIXEL graphics codec implementation (runtime) Changes: libsixel (1.5.2-2+deb9u1) stretch; urgency=medium . * d/patches/0001-Add-malloc-size-check.patch: fix CVE-2018-19756 * d/patches/0002-assign-default-error-message.patch: fix CVE-2018-19757 * d/patches/0003-add-limitation-to-width-and-height.patch: fix CVE-2018-19759 * CVE-2018-19761 is not security issue * d/patches/0004-size-check.patch: fix CVE-2018-19762 * CVE-2018-19763 is fixed by 0001-Add-malloc-size-check.patch * d/patches/0005-check-error-for-jpeg_read_scanlines.patch: fix CVE-2019-3573 * d/patches/0006-check-number-of-repeat_count.patch: fix CVE-2019-3574 * d/patches/0007-fix-memory-leak.patch: fix CVE-2018-14072, CVE-2018-14073 Checksums-Sha1: 164e7c7dedbf9f678d33cfc183ddb814a8704e96 1897 libsixel_1.5.2-2+deb9u1.dsc 3578c75636113fd90e6fed9ae450e00faebf4a03 5960 libsixel_1.5.2-2+deb9u1.debian.tar.xz ec497666a417813446b175e6f2b07b53bf6bfbb8 6991 libsixel_1.5.2-2+deb9u1_amd64.buildinfo Checksums-Sha256: 4208398601bca60f81cab192c6bf12271b18cfa5d6ee8468f09746b61f78727f 1897 libsixel_1.5.2-2+deb9u1.dsc 6e507bf58baa69264ae02de2d557cf5032a662f88932d3dfda9200a3388b5a84 5960 libsixel_1.5.2-2+deb9u1.debian.tar.xz c6c8fdb60e6398450888eb0b02f7454336be77a03589edbc8c541d17b3ab743c 6991 libsixel_1.5.2-2+deb9u1_amd64.buildinfo Files: 0a0e9a82082ba654659f8e8a5f7f0fae 1897 libs extra libsixel_1.5.2-2+deb9u1.dsc 5fa12aa4c1609dd9c8ed8f7391b96178 5960 libs extra libsixel_1.5.2-2+deb9u1.debian.tar.xz 6a4dd6d645f41bb6ce1e8ba28c8ddea5 6991 libs extra libsixel_1.5.2-2+deb9u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEmUUrTdKL7qyKtckxsGZi7JwMFAQFAl2mbBUTHGtub2tAZGFp b25ldC5nci5qcAAKCRCwZmLsnAwUBMk4EACulSepAymPRJ4zsKt1zF9xDnpRxSUA TOBm3Mhd/46+D+aTs7JWkTmifEV4timGDWCa6OirzCrUZyH9OM5XtL0baaRksnLA WzTqVz5yIxObrLzpTIFCQoolfI0bKqT31ftCWBMSMJLo/mu2PJL7cZ9gfdZ3k/uj Dvdd7vZl7SWOTne6PrHqu7q6UMQbFRgjFcGpt4yWv1JqBIFyYFa1mz6nvxk3irbZ jWQ/TCQymqm9YZpW9i1DBOEu8IZuzSjR0Hf3amhNhtdv21XbmFu8MTBaIxsDqHcK JJhBJ41WgNGztX6VFwtMDJ0xMKKF/1ptkCFAQXPplR3VTR54ghlb+JfBLN/fFKXc GnO3NK+R6WlXNVTHtl2lDbyChbqh40OncdOJ2sqmYUiw1RL/MFHtuh8p5k9OwOUA AkqtwlGPd2N7ajU6ZQwFNC7MIfkLt0fbfZ9dshUogHy4X0KJ4Vb4VPaj/AYKTp3L 1lI1ahKgNeKh33pOoDgzOPqES/bilLm0oFtehQvouS7dEAIT/qrHeX8HYHtMZN5G BI5rzHdHfop/exuYYBbw0PvEXDFnXR2B0kx7Ba1qlknVc8SjP4vuiAaMcyU7L4Hf NOsz2me7zUlTYq6DA10pYxZZGS6e3OhZkm6cHe4VuVxmr/gQtrg82znw6jVLBpCJ w3wc7ajaZDqkVw== =r5Lv -----END PGP SIGNATURE-----