-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 24 Nov 2019 10:42:07 +0100 Source: freeimage Binary: libfreeimage-dev libfreeimage3 libfreeimage3-dbg Architecture: source amd64 Version: 3.15.4-4.2+deb8u2 Distribution: jessie-security Urgency: medium Maintainer: Debian QA Group <packages@qa.debian.org> Changed-By: Hugo Lefeuvre <hle@debian.org> Description: libfreeimage-dev - Support library for graphics image formats (development files) libfreeimage3 - Support library for graphics image formats (library) libfreeimage3-dbg - Support library for graphics image formats (debugging symbols) Closes: 929597 Changes: freeimage (3.15.4-4.2+deb8u2) jessie-security; urgency=medium . * Non-maintainer upload by the LTS Security Team. * CVE-2019-12213: stack exhaustion caused by unwanted recursion in ReadThumbnail (Closes: #929597). * CVE-2019-12211: heap buffer overflow caused by invalid memcpy in PluginTIFF. Checksums-Sha1: 8109782e1452f90e26423a555c60952fe6912326 2018 freeimage_3.15.4-4.2+deb8u2.dsc 13c6c4ff3e180c2bd949921172e3455f63e25845 35664 freeimage_3.15.4-4.2+deb8u2.debian.tar.xz 607d8848ef5cb89a3f3c07ff918373e08e103456 1221704 libfreeimage-dev_3.15.4-4.2+deb8u2_amd64.deb a14da97e6ad159370da3044b098f689f5cd30b5c 333372 libfreeimage3_3.15.4-4.2+deb8u2_amd64.deb d7d6fdfcd8da05576ecbbf56c32f7ebfdc090cf7 1198516 libfreeimage3-dbg_3.15.4-4.2+deb8u2_amd64.deb Checksums-Sha256: 8a9c5591f103907612afd93e7340361730b603cd31cf0eb5a4f4fea684a1d34e 2018 freeimage_3.15.4-4.2+deb8u2.dsc ce74391e2b2f250938459b7934cb7d8b713f41502bf2108555139a27a7acc5cd 35664 freeimage_3.15.4-4.2+deb8u2.debian.tar.xz e91f886fc77092271b5c6fc4e67e30388ce65e8335442890aca42c143391f411 1221704 libfreeimage-dev_3.15.4-4.2+deb8u2_amd64.deb 7443a80e7381ef9fb35b6d5aa22beaf0e5fab63315bd879280e6f899a3837715 333372 libfreeimage3_3.15.4-4.2+deb8u2_amd64.deb 7b2b1bc105003de167cdd76672e5c84d76573a6de7fbbf3234131bbe597f8886 1198516 libfreeimage3-dbg_3.15.4-4.2+deb8u2_amd64.deb Files: 17d900666d863602c65fc682a6c31bde 2018 libs optional freeimage_3.15.4-4.2+deb8u2.dsc fab0fa9e8b3108cddfb49827720be4b4 35664 libs optional freeimage_3.15.4-4.2+deb8u2.debian.tar.xz ef264307fd2999508ef8ca96ca337e83 1221704 libdevel optional libfreeimage-dev_3.15.4-4.2+deb8u2_amd64.deb e314bb1545a54d8a82460b2ba78e5b99 333372 libs optional libfreeimage3_3.15.4-4.2+deb8u2_amd64.deb 4a94389b5592030bcdbfd69061cc3b9e 1198516 debug extra libfreeimage3-dbg_3.15.4-4.2+deb8u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEeDb9QWtkMa2LX4zREeMFjl5EGkIFAl3vulgACgkQEeMFjl5E GkLb1Qv/TdobRRwyFtX1N/4R5BJPHU9iDlMYRIWVhmMT4gzQGupDjt2FcHHjxpUc MfbIud+rH7bcmU/73Ps4y9Lw0INBsw6bvuWZvdTD6c5VjIXUpfI+0nt13MQ5E3s2 gOK8/h9zCvA4uMs9PG/shQNf9EfKcaYG3eKyJPfzQcUxtnvpbwwF85gmrlrZaMMc guMXEHnFWYbJWmJN+llw3KnwJcuiONDGB+mE0xy65SCHT2+ggjjNJ1qXZEORYtCj ljSJwpn1QwmOZZESVMQhzoz7h1voD07/2Ebzs3z0YaZe275mWBJFVi3x/H6oMxBG zuTefHF603XFxj9v/ZJZwGi+c0+eaOylpPq1h6kYKJOzyPPE8IwQqcInatkgDfUQ yDxzSZYBxhlFu5s4nr0d2makDhZW4AvNShvNrnbqFqWTiPdoOlaBMqzYAY9E/liU DHES0BZSte2xiSkxNxXZ3I4GPgKBEZ6Eq873MF8u2guEFaBsqkLvzfgClwDxlopv TOdiACTN =2dXz -----END PGP SIGNATURE-----