-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 25 Apr 2020 17:03:02 +0200 Source: libgsf Binary: gir1.2-gsf-1 libgsf-1-114 libgsf-1-114-dbg libgsf-1-dev libgsf-1-common libgsf-bin Architecture: source amd64 all Version: 1.14.30-2+deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Dmitry Smirnov <onlyjob@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: gir1.2-gsf-1 - GObject introspection data for the Structured File Library libgsf-1-114 - Structured File Library - runtime version libgsf-1-114-dbg - Structured File Library - debugging files (basic version) libgsf-1-common - Structured File Library - common files libgsf-1-dev - Structured File Library - development files libgsf-bin - Structured File Library - programs Changes: libgsf (1.14.30-2+deb8u1) jessie-security; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2016-9888 An error within the "tar_directory_for_file()" function could be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file. Checksums-Sha1: aa462d38c97e6a8417374e0a27466f67c68c98a0 2524 libgsf_1.14.30-2+deb8u1.dsc 5eb15d574c6b9e9c5e63bbcdff8f866b3544485a 582556 libgsf_1.14.30.orig.tar.xz 3644a1c4b598a91cd8963900c47c109cb856685e 13112 libgsf_1.14.30-2+deb8u1.debian.tar.xz b6f72b7f7cb32b906036f4ee6a63b2250ae171be 75856 gir1.2-gsf-1_1.14.30-2+deb8u1_amd64.deb cdcf85684fce31857bc5d307710ea3a2b656b504 158776 libgsf-1-114_1.14.30-2+deb8u1_amd64.deb 619dc569529928d4b9046fff972c749948704dda 334058 libgsf-1-114-dbg_1.14.30-2+deb8u1_amd64.deb ec5d127bacb0f8cac4a61623c55e504de3046071 258674 libgsf-1-dev_1.14.30-2+deb8u1_amd64.deb 45862f8b2ef6537c8cfdb68712240b6c7acf6581 152270 libgsf-1-common_1.14.30-2+deb8u1_all.deb a8b927b1370e83c795997b73b99899486679b850 78760 libgsf-bin_1.14.30-2+deb8u1_amd64.deb Checksums-Sha256: a6c32f6b68829c8268aed1cb57c3d667f1e9a795cb15218be6af335bb980d43a 2524 libgsf_1.14.30-2+deb8u1.dsc cb48c3480be4a691963548e664308f497d93c9d7bc12cf6a68d5ebae930a5b70 582556 libgsf_1.14.30.orig.tar.xz 02323a589823ae7842bcd7fd3094354c0ecd02614bc54a68054b19ab2b08b53e 13112 libgsf_1.14.30-2+deb8u1.debian.tar.xz cc5657c8ba5f41dfee0c75376ee821339f84b9dc029be7b10fd8b228f1aba97f 75856 gir1.2-gsf-1_1.14.30-2+deb8u1_amd64.deb 2440c1802e97180aa50bc0ff4a1a65b22cc17b20f0578ee2c3bc6254d1d98760 158776 libgsf-1-114_1.14.30-2+deb8u1_amd64.deb ae6d7af764e7454d6cd1cfbf3010d2212fb579bb7ebb70d9f58db398c6d5e57b 334058 libgsf-1-114-dbg_1.14.30-2+deb8u1_amd64.deb 953e28fb60dc779a3cda7d0f5559d18bc9812a9b26f3145193678b2072421458 258674 libgsf-1-dev_1.14.30-2+deb8u1_amd64.deb aff8a9baa5374a31e1a5bc0323f1fb10c4b165b21e4918c7711a679b0a2b285b 152270 libgsf-1-common_1.14.30-2+deb8u1_all.deb 1b883ae9472006dddc77e8a57bb15717fc89c6229ff4646fde6d506ac73dede3 78760 libgsf-bin_1.14.30-2+deb8u1_amd64.deb Files: f36d350552348286fdb0cb12dcc60186 2524 libs optional libgsf_1.14.30-2+deb8u1.dsc e7b672ef37ef6a853ce149c03e4d3a63 582556 libs optional libgsf_1.14.30.orig.tar.xz 281daed8c02746c19e3e9ed83115228d 13112 libs optional libgsf_1.14.30-2+deb8u1.debian.tar.xz 375f3d0c26a447eda9660b43f5696cb5 75856 introspection optional gir1.2-gsf-1_1.14.30-2+deb8u1_amd64.deb 4c8975ebdc2d2772af8b29bab22bb6c9 158776 libs optional libgsf-1-114_1.14.30-2+deb8u1_amd64.deb 15e2e1cdd4d19ce6289c1a8bdf02cb1d 334058 debug extra libgsf-1-114-dbg_1.14.30-2+deb8u1_amd64.deb 1486a1e63e990407166170c3d7ba457b 258674 libdevel optional libgsf-1-dev_1.14.30-2+deb8u1_amd64.deb 5cfc199d6128bd20436162b030fc0528 152270 libs optional libgsf-1-common_1.14.30-2+deb8u1_all.deb 4ad824cecde37ac2974cf755ba1318c5 78760 gnome optional libgsf-bin_1.14.30-2+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl6kWYBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYRx0UEACxihHOlmComjEKKLE6gxly+5bYKulc yHcvgPcFrJUTXmIJjpZ0sXpp3LE5T/OrzdjYgOIiueAmHqMSnUTj28bRatS5+T3A ldBb5M5vYyk751HQ3Sclc+7dQ0vM3UZ32amZjE6eL4HgdZXIMQnEuUHg35znnlGL kXAmrzoREQOfoiAaNqrtGnlL2/qLc6At4m0RG8J9moW0iNIMyxVQcBdjYngnpVIe NbMddS8NJwVJeQVyTImQqHGH5jt5K2GHEvKIhWDXyhTciyzKJ114QVT/bjiDGc8q lJXMJ/gesW5d4r+JyEbb4HtOtmQ/WzxjWKmS2robPinzCkynIUtC+Wy/qu6lmc5g lDpZ7HEmY10NxSPfP/FFf01y2b7Cok4JKaudEPPkIs1rDbq+JwdTyJ6WCGteEw2P TaRs0Dpwc9qb5npfVrbzx+hN758bCg/c8WT9OGKLKFCkL3+gw5bd/3oJ1sUo1B3H uOGQNTdhMFsyeDfNerkNZBIOvCBBfF1cW/jlZCJ2lr7sM5RFo/5XBdQtwmwexndC amvwd9FbCX5YsRXW13OXJxXFEiYv4NmISI2ySTlZNFamOX9jpTBY35TcPwExlpTb d2aN8neziXGk39bhc6Apgf9TyFihqoZkyCL4rDUyIkrjvJ8VxHwd7O8KSo0JBMJu p2iPj3C2ApKf5w== =e+KC -----END PGP SIGNATURE-----