-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Dec 2019 18:55:43 +0200 Source: jhead Binary: jhead Architecture: source amd64 Version: 1:2.97-1+deb8u2 Distribution: jessie-security Urgency: medium Maintainer: Ludovic Rousseau <rousseau@debian.org> Changed-By: Adrian Bunk <bunk@debian.org> Description: jhead - manipulate the non-image part of Exif compliant JPEG files Closes: 907925 908176 932145 932146 Changes: jhead (1:2.97-1+deb8u2) jessie-security; urgency=medium . * Non-maintainer upload by the LTS team. * CVE-2018-16554: Fix gpsinfo overflow. (Closes: #908176) * CVE-2018-17088: Fix gpsinfo overflow. (Closes: #907925) * CVE-2019-1010301: Fix gpsinfo overflow. (Closes: #932145) * CVE-2019-1010302: Fix iptc overflow. (Closes: #932146) Checksums-Sha1: e4de067a55be9b684b2c7b011d916eebdeb7855c 1711 jhead_2.97-1+deb8u2.dsc ca4965a19d60078a3fe2cfb6d3635a083f958f2e 68361 jhead_2.97.orig.tar.gz ea49f225f34671fbe7a6d5ebef25aec667583e67 7100 jhead_2.97-1+deb8u2.debian.tar.xz 57368f3a6ef0bed906c9d9eb230c54a2a6d92c59 47460 jhead_2.97-1+deb8u2_amd64.deb Checksums-Sha256: 3f524bac080d63069cb74d2d313250da50a020f34e0ed405f77ce1b4ed46edee 1711 jhead_2.97-1+deb8u2.dsc 04b55c5cd27882f631c2b25316803d8ac81c6d2408e6129ca47019c018324f17 68361 jhead_2.97.orig.tar.gz 8761de419640227de6751a2024c95cd863feffa992aa7378f53ccf8c7dca0a2a 7100 jhead_2.97-1+deb8u2.debian.tar.xz 09bfb6cde7e8bc96e2104fcb38eba6269ddbf7a8f8c0d426bfc2da3ec8450b8e 47460 jhead_2.97-1+deb8u2_amd64.deb Files: 626ff181de1eb32a91d67c5444cef98c 1711 graphics optional jhead_2.97-1+deb8u2.dsc 23b037d0c54211973a3951e41a97c924 68361 graphics optional jhead_2.97.orig.tar.gz b9a5950ecbd952c67c95ee9bcf1422e9 7100 graphics optional jhead_2.97-1+deb8u2.debian.tar.xz 0efb4f484a4feac4cbd59260d3316a92 47460 graphics optional jhead_2.97-1+deb8u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAl4Ld+gACgkQiNJCh6LY mLHnVw//TQvxHRHlfifJwf0P8oXlis236+86X3OmR294ErqQmUYWgnPMCn71QXIz rfg9sYWZWwh5/WdR3lZwaUdk1PPL7uwqbjpF6aAOyIkiU7MzNG1cjets8V165Pyq cpqCwIsQskvdoT0X3I2bO4J+L6bjZGt+6kujrezvgsrjUwERWAxDTsx3g0IWrRf5 wZeH3zOeEkOGU5IDieEH3qOVSd9GcY+4xeP2GJPVLMykfkI9oUySYPXAiEfEwpdd GI9DymbPBqGYytUayR094Vh18NfeBXRYC9gaGhHXA81Ic9XTojxIicvsYL2DG1JV IzbFfZNp4kB23MkYq+gyv/oVINDofnwQbYCQ9C2Oae55O3G3GHu8AqPbP6AT+wDp 7TdlrEGUJP2NaJ57/xQut7SmwnbuLu2J8fzQRwgeakP1vnLpqS4zeW4t61/YRFu8 h6NLAcfen3nZrw4AdARZZemHg4QmngICIar/fpf5msF84V2xxJZVTzQGxF9b2N3D FN0yt1IisSfHlVJ/KOmrnLz3yxZit9MkaldOwXXTPd2l2U1jgRCTpVIiT5QB3SDp fm1yWnxAlLmBWLBuob0Oj4uzVGaiFYsI/i83RY4ji6SUMhWTypPnTZ0dMlSN0aT6 +EbwiQtEjDUxQelg5IH/FkzgDiLjzVNU6eW3Cjhzk1ysBnH0yjY= =Akjh -----END PGP SIGNATURE-----