-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 18 May 2020 06:23:41 +0200 Source: libexif Binary: libexif-dev libexif12 Architecture: source amd64 Version: 0.6.21-2+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org> Changed-By: Mike Gabriel <sunweaver@debian.org> Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Changes: libexif (0.6.21-2+deb8u2) jessie-security; urgency=high . [ Mike Gabriel ] * Sponsored upload by the LTS team. . [ Hugh McMaster ] * debian/patches: - Add upstream patches to fix multiple security issues: CVE-2016-6328, CVE-2017-7544, CVE-2018-20030, CVE-2020-12767 and CVE-2020-0093. - cast-unsigned-int.patch: Cast to unsigned int before shifting left to avoid implicit behaviour. - exif-loader-undefined-behaviour.patch: Prevent undefined behaviour when left-shifting in type 'int'. Checksums-Sha1: a8dcb25572c3f01216dc3c1fa5dcfa1efdd5b8fd 2127 libexif_0.6.21-2+deb8u2.dsc c1d7ea2d29d190a7d73aff71e609089d21661951 12008 libexif_0.6.21-2+deb8u2.debian.tar.xz 438b4ec2ade04ea2111641b1cb3a4bea34766b69 397804 libexif-dev_0.6.21-2+deb8u2_amd64.deb af19ee6e5419f132409a051c5c3ae7e8c6306049 323968 libexif12_0.6.21-2+deb8u2_amd64.deb Checksums-Sha256: bcf6815d100e51c86884f5b9a6c84cdcff70a69468a2d3a920155d6cd0f51c3a 2127 libexif_0.6.21-2+deb8u2.dsc 281d4e9185089cf220024d25de359be64711bc604163e860e5e1fe634c8b567b 12008 libexif_0.6.21-2+deb8u2.debian.tar.xz 24fe0f459c447bfd93956ae33de485afcea9743bc21a4f16c3897cc05adf91bc 397804 libexif-dev_0.6.21-2+deb8u2_amd64.deb e24dba97c55d307023921358ca977960ca8e3fd7093e2cab49d441dba95e3d5f 323968 libexif12_0.6.21-2+deb8u2_amd64.deb Files: 077f0660170256a813a6bc797ed3f2d1 2127 libs optional libexif_0.6.21-2+deb8u2.dsc 52af3e0f310b513d2e21b3052235a2cd 12008 libs optional libexif_0.6.21-2+deb8u2.debian.tar.xz 6157fc4416b49c73653d575832c541b9 397804 libdevel optional libexif-dev_0.6.21-2+deb8u2_amd64.deb 9ac0f65fdc7566d932147927ee0b53c0 323968 libs optional libexif12_0.6.21-2+deb8u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQJJBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAl7CD2cVHHN1bndlYXZl ckBkZWJpYW4ub3JnAAoJEJr0azAldxsx37kP/2Y3coAFUYesASDq0Mb3Kq9XQrDv tnDG0y/cbjbb5XVt7upBPZhwcoy5jsl1NoNxRqvgWDZY8SsgBiU4ODFHG/9jC5+L 5erntIMKa+o2azOkCicsigS5k3CQO+gls6K29bWzp40MWwCER4bJGW36nD6GCx2C ALdyXvxHBBjJgvEznartz5X1caTvPI/uVNoe4PjfdgldE4W0J8HDneN19qwdW3DO LztCISi1wM2mlnscHKvtmjhszCtW8Owryt3HCvs4ou5bhMiPQXwvLQ1t/Mufl9oM SVTpbcc3bLZHEq6IV0shdO/ZJLOqUj4K69gfbzptjYMSoyBiKW+OCO0Ym7KwbH5d Wed6DttPpMyevx3nxSUJpsIk3JI1oAcMVBwITrhlAigw6M3sXnudLUMsvJMdplpn EfPHmHT3brL22YUS/LxlOSWgCnZQpqeIr7YoAoVnaWml+iiUZCaokP1x2/5nFsuN GXU0OJxCkYOlCMeIjyXojB1FdqqH3ZbazWfiY7fp8VAD28ATvNRrDSmVcf56ObWR LHlhLw1vkixvtUQ8zlOrqDUdkSV6yjfFOIQWLnCjjgpKoccXzs4str9Ydgfjwy2N OZQxob4/jloHeptyntrlYx6X0ATjO+yGInTIyL44N94FFxzZCVYiAsWU/PieQBas iV73euyUPS9+0Jd5 =MQwV -----END PGP SIGNATURE-----