-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 08 Mar 2020 14:49:21 -0700 Source: libvpx Binary: libvpx-dev libvpx1 libvpx1-dbg libvpx-doc vpx-tools Architecture: source all amd64 Version: 1.3.0-3+deb8u3 Distribution: jessie-security Urgency: high Maintainer: Sebastian Dröge <slomo@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: libvpx-dev - VP8 and VP9 video codec (development files) libvpx-doc - VP8 and VP9 video codec (API documentation) libvpx1 - VP8 and VP9 video codec (shared library) libvpx1-dbg - VP8 and VP9 video codec (debugging symbols) vpx-tools - VP8 and VP9 video codec encoding/decoding tools Changes: libvpx (1.3.0-3+deb8u3) jessie-security; urgency=high . * CVE-2020-0034: Fix an out-of-bounds buffer read on truncated key frames. Checksums-Sha1: 581c942571b6df52b5cc1582345b7c817a5f4083 2041 libvpx_1.3.0-3+deb8u3.dsc fd90afbdba7905b9b3ab6c707c41369627d208e9 2077846 libvpx_1.3.0.orig.tar.bz2 f3c9bda5c439b0d349bae350a240719e342955dc 13144 libvpx_1.3.0-3+deb8u3.debian.tar.xz 321e8b341f5efba8edaaf214a4c3fa729ead12c5 192176 libvpx-doc_1.3.0-3+deb8u3_all.deb 61ede0fd6aa102146708778a9106c9650bc94ca0 685366 libvpx-dev_1.3.0-3+deb8u3_amd64.deb 3dd426f4a392f393393690d65948ddae511c01a0 600084 libvpx1_1.3.0-3+deb8u3_amd64.deb 40e9363f05dcb07882f7f0ca02155c32eb407a30 1376406 libvpx1-dbg_1.3.0-3+deb8u3_amd64.deb 14fb47f6c5b8bf9af5c6be524b9f7dcfea11f37f 81002 vpx-tools_1.3.0-3+deb8u3_amd64.deb Checksums-Sha256: b9be36d941f9b1b64d80dddfe17a35bfc239384c0f34308d4769b1ad3df4b69a 2041 libvpx_1.3.0-3+deb8u3.dsc bd5af97b74d53a111b48852dfcd1791b2c758f1fe972833b363fe34a83a7750a 2077846 libvpx_1.3.0.orig.tar.bz2 5b7d62567f4bfb357a9344815b4cef5416c7bee82832ec6671340f6bba083182 13144 libvpx_1.3.0-3+deb8u3.debian.tar.xz c140f40d1833e54be86b10e57227c524ab8aa4eb89d86613ba97efbc869da802 192176 libvpx-doc_1.3.0-3+deb8u3_all.deb fc73d5a39442bb1b17fe750f3be1bc722dea7c803509982fad7c63a1ffa7d93d 685366 libvpx-dev_1.3.0-3+deb8u3_amd64.deb 46293416ff55cbe37773a6f8ee37ff9b6b8384ae37a47202396e1a68ec675dd3 600084 libvpx1_1.3.0-3+deb8u3_amd64.deb 68a70459369042f9496f381be39ee109d7c9918cd0de7c0674bbf0bab131b6da 1376406 libvpx1-dbg_1.3.0-3+deb8u3_amd64.deb abc6abb8ed3650fb53be4327e0fa940cd43d4423955d7f012d94054fe4a33425 81002 vpx-tools_1.3.0-3+deb8u3_amd64.deb Files: c74714cfed3838baf4abdd3dfeef72eb 2041 video optional libvpx_1.3.0-3+deb8u3.dsc 03c43425a879bb9cb749052e70ae07f9 2077846 video optional libvpx_1.3.0.orig.tar.bz2 f8483139f05cd29686e82a3594f370a5 13144 video optional libvpx_1.3.0-3+deb8u3.debian.tar.xz 1478d93fb522c3717d21599585d36d70 192176 doc optional libvpx-doc_1.3.0-3+deb8u3_all.deb 6d201ed12f6a0cc5be9c82f3f8927839 685366 libdevel optional libvpx-dev_1.3.0-3+deb8u3_amd64.deb b96a62e98cc3bf0c5fab17655394ccf1 600084 libs optional libvpx1_1.3.0-3+deb8u3_amd64.deb 8471c1f9d3429d8975183af124c34408 1376406 debug extra libvpx1-dbg_1.3.0-3+deb8u3_amd64.deb 77878b0ad2f76a7bb38fa93bc0b39175 81002 utils optional vpx-tools_1.3.0-3+deb8u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl5mjAEACgkQHpU+J9Qx HlhtiQ/+MMLYkHYuQs6Bcvu01lnFxHOcdATokVznVrQ5/giB8Q8S9DwwYvBXyJuI i8Dx3Bu00cwusJWZBrzichv8lfQzS2AHrwcI+APHmBGm4qPxBhMwGR0du8cuwNiX 2Ih5N2vPttgrVyaJ0RJZFXlvyqPF9FgnWG6eMnMEuWdW9qaPPUXzlWvKTzJVPmLA uweMYArDy4MR2MXoJMTLuIoA57bK2OjfQYfyReKdxJNsJQ3yQ0xFLOTojeWiYiRW 1zpWbzqgDCyoJQhDoGfNz9i1/pG4EeX84TYulsrPga+By59lb1bBxKjdNRJAyPar 1cU4vIxlNFxgPm7fjO8FbTyW7LApJezCDJTNw5ngDbrROOKp2MeWrTeju/Q2zBuw vQclGnoDFk6wMJgcaT98I6d2byDOaLKw9aj+Dxc4Vuet1c71HGmtEBWlahcqPD4S nG2ny8jKA7tiy70H96v0YuM0GDNY/Zlcg3aM6u7RX9I73SGMuvj+q1lcFnx+L/AW Kt8T/wdP3RqJ/L93Gd/kBWfkt9BkvjJkFEAbv3Ufda9ZwqfSJDP8Z/RaP/j8nvm8 27WCe/UsqN6YyvS3rvDm0VjsveFDAfwOQRRDZJe8AALCSXbbCvBD1nXjZXiuQtOb 8qxJjlzQ4qg0fNUDH168KRWrYX9hXvOUwa4ft4jhTLA4Q2A4Ucc= =VYJe -----END PGP SIGNATURE-----