-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 30 Jan 2020 10:42:01 -0300 Source: qtbase-opensource-src Architecture: source Version: 5.11.3+dfsg1-1+deb10u3 Distribution: buster-security Urgency: high Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org> Changed-By: Lisandro Damián Nicanor Pérez Meyer <lisandro@debian.org> Changes: qtbase-opensource-src (5.11.3+dfsg1-1+deb10u3) buster-security; urgency=high . [ Dmitry Shachnev ] * Backport fixes for two vulnerabilities: - CVE-2020-0569: Do not load plugin from the CWD. - CVE-2020-0570: Qt tries to load invalid library from CWD. Checksums-Sha1: 7e0ab2157fc16fc63bd7c2127867ebfdb0e1d44d 5206 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3.dsc fb306295672cc3c47bbf7b207676723b99df5e1a 45155472 qtbase-opensource-src_5.11.3+dfsg1.orig.tar.xz 55d7f51ec0c37eb848707a2e5d40ae39a9a4d985 243308 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3.debian.tar.xz fe3c6e104d5663f66c62121dc115c2eb8c8992a1 10588 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3_source.buildinfo Checksums-Sha256: 9bf8665dbccc43683a1acb478c96cc2137e25f5983e23518d8f149286665c41a 5206 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3.dsc fb6707c7f9f65b7160879d3bf6d05b3a9a796172c1fc47962b79f5a45c375a22 45155472 qtbase-opensource-src_5.11.3+dfsg1.orig.tar.xz e79a6a0899f69d726cf233697fdcee6b354eea4860e62a0234ffc5d340814b8f 243308 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3.debian.tar.xz 7bf992ba0fedcc4ed7e8b2d906babd4345765c4bbe2822cbe9fe8439107eee03 10588 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3_source.buildinfo Files: 477b780e04b7f3d70a52c367d3a457ac 5206 libs optional qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3.dsc 1bd73b1d2982bf3bde8f27a98eb50113 45155472 libs optional qtbase-opensource-src_5.11.3+dfsg1.orig.tar.xz 3e17aefca771ba3ff5a4cd0c6973b973 243308 libs optional qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3.debian.tar.xz 6c857923ed50bc387986f7358e6eb597 10588 libs optional qtbase-opensource-src_5.11.3+dfsg1-1+deb10u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEEt36hKwjsrvwSzE8q2RfQGKGp9AFAl4y+1MUHGxpc2FuZHJv QGRlYmlhbi5vcmcACgkQq2RfQGKGp9A69w/8CD68SKsqX/gwL8L+45NxMoQZy2qG X0N712wIkmOUgjQN6EZE+Ep5sJPA2KnMnPylJTAPFoiyUDpNFEk+r4TfyRmhEiXG wV4EsdCh0Df5XWynKtw+k6fCXpeGRC6VlRIL1nhhIwCRrsYN0ch/MfLABZKYY2pY ebkV8RB+dcbbehgIzed7iLfPAL7Nspx1mMjG30dL2UMisdfiMjjNFG5ykCj5ufiJ DCwusb7MRgGj0TeRHmcJOV5N5mc1CJUpWK1KFE7ni5iYLOnhcHWy0Vlxjicx3Dqa 6Il96CTQJkztMkMMglAQkA5yjivo2SIIFx+JqMnUSLNd8tIwmI4YplKac2hx3lpy aV95iWFIVJDfyKO8af57WMJTDUTxVteFT4ZXOekIXoMGXVF9DR655uroDJsuedGK Xzk0uvHTN8fh2OEWjwkBwRTgKgpPRnORBRkC47Ei4vatxMvUcvyO3ffFp7D8fKHV 0ukuSN8CbUsy6GQFNvA6xMMdd78K4DtpmL5YxToWIYC9oHG/EQsoqPn8jGkzLNQ3 xdJClVHYcy7mDtteBuPoYMNKz4kT/7KbPVDw5T4fDm6waloYbwt4QvKVXiiDohIt PmmsF9n93UuvNdpFtF7MEBfJeTGyz1RS9nWvEdHE30KkvV8boKts1v1tVpkkshB5 H69QRpjgjgkPH40= =+zLG -----END PGP SIGNATURE-----