-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 16 Dec 2019 11:08:42 +0100 Source: libvncserver Architecture: source Version: 0.9.11+dfsg-1.3~deb9u2 Distribution: stretch Urgency: medium Maintainer: Peter Spiess-Knafl <dev@spiessknafl.at> Changed-By: Mike Gabriel <sunweaver@debian.org> Closes: 880531 905786 943793 Changes: libvncserver (0.9.11+dfsg-1.3~deb9u2) stretch; urgency=medium . * CVE-2019-15681: + rfbserver: don't leak stack memory to the remote. (Closes: #943793). * debian/patches: + Trivial patch rebasing. + Add 3 use-after-free patches. Resolve a freeze during connection closure and a segmentation fault on multi-threaded VNC servers. (Closes: #905786). + Add 0002-set-true-color-flag-to-1.patch. Fix connecting to VMware servers. (Closes: #880531). Checksums-Sha1: 743692ad8dc1a4a4569f447a02b719174e016aa6 2463 libvncserver_0.9.11+dfsg-1.3~deb9u2.dsc 9ff36c8dcf566f4badde6e3d199a74a723e384dd 22652 libvncserver_0.9.11+dfsg-1.3~deb9u2.debian.tar.xz dcbb4a90bfdea47044ae972040874f98f939e20f 7212 libvncserver_0.9.11+dfsg-1.3~deb9u2_source.buildinfo Checksums-Sha256: eb6e0ecbceb91e96c02422a0d937b9a1b0bfa2d1ec36b3e01d60e43ebfcd70d7 2463 libvncserver_0.9.11+dfsg-1.3~deb9u2.dsc b600e935b5a25b52192407e03fc91e4aa667fc10e2cf0ef99684c3d5c88dbd89 22652 libvncserver_0.9.11+dfsg-1.3~deb9u2.debian.tar.xz 5d54792938c6709e41acb1096a8332990927fde7b382fe4f5eae380b2246aa36 7212 libvncserver_0.9.11+dfsg-1.3~deb9u2_source.buildinfo Files: 43ca10dc7baef25e62dc2f0e4fe2dc9d 2463 libs optional libvncserver_0.9.11+dfsg-1.3~deb9u2.dsc 06d5745952a59ee91d7521e8c2d6a6ca 22652 libs optional libvncserver_0.9.11+dfsg-1.3~deb9u2.debian.tar.xz 560f77c1a3749fe1e646aa05439ab8f0 7212 libs optional libvncserver_0.9.11+dfsg-1.3~deb9u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJJBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAl33WOkVHHN1bndlYXZl ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxohsP/1wxOd3RifEBFy6rBGESi5qmNAGT +3FuX98idptSXQQIlAGckbChKWFKbcaQRtfS2RkTjhGYWiGs/AE5qwC170v26OrA 1W0kf2Rm1k9OxWLec309b0wg81GCLTUcKamSfGXotjTk2lUYw0Rd7B0CLHxgvuPe fBsydEHVnkw5U8lYzX2tUfEJQTRHnI2yICFOUjEAGuB0Dv3Rkm2/IjLxH57rOrcH GP5Iu4cJmmWyhUBkLy6v/x5KWV8WmWe6Ux6Hyo9uKVyuNUDm5oJOwGCqmij0aV2w P7mbhf9BJmvLc2wX97hC+S3uNJI/xdbfH4vKwFWvQlcRjZ/af2ObkQbxKZ/4mEGK 4eGWoykBRndqiL4WMFgmvsV46cx95Xw4NZu9O7N5IiKBiLQxDLgeugOoDlcn+cLH KEe7gjbdxRhil86m+w/YsSeLkbVGsFsmHkve36jDAmIHQvuvAopb2VQ6b5JLF8jF MZGIloMmDHEfNdjy8WO2c7l9ZWJejeFQ72t+y43fzlUdEVLY/5bmSSi0VOgsacIh AZzh7anL2DT/D8mU7VbCkhV9obGbNIKhERVOeXCgBaMU9L05RBEPtijL9f/kFVGH pfrv9/m5ZpxGZseicpa2o3TW8qyLRis/eHgOKT3h+DHMwBX/vxur5lESoSUOxhXO 2wA1K03rSKIxwWQG =6oiL -----END PGP SIGNATURE-----