-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 03 Jun 2020 17:49:58 +0200 Source: graphicsmagick Architecture: source Version: 1.4+really1.3.35+hg16296-1 Distribution: unstable Urgency: high Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changes: graphicsmagick (1.4+really1.3.35+hg16296-1) unstable; urgency=high . * Mercurial snapshot, fixing the following security issues: - ReadWPGImage(): Terminate reading when a pixel cache resource limit is hit rather than moving on to heap buffer overflow, - WriteTIFFImage(): WebP compression only supports a depth of 8; fixes use-of-uninitialized-value in GammaToLinear. * Update library symbols for this release. Checksums-Sha1: 9e5a9597a582020afd7b34fa559d4db9ed53f08c 2952 graphicsmagick_1.4+really1.3.35+hg16296-1.dsc fc56b0ca4d4557c186190e33435d6eae8f94ede7 6029156 graphicsmagick_1.4+really1.3.35+hg16296.orig.tar.xz 699aafe93cc74c47e36bd7bf250315d15225f8e2 145968 graphicsmagick_1.4+really1.3.35+hg16296-1.debian.tar.xz Checksums-Sha256: 530235680c47f1f0727d798019f1e3297ce32d8dd1b8bbcc12bd47fcd7f0b4d3 2952 graphicsmagick_1.4+really1.3.35+hg16296-1.dsc 5ac732bd239df3c0abad12bf3a3680f35c70bc81c5d5cd668a30c5fc22d8c1dd 6029156 graphicsmagick_1.4+really1.3.35+hg16296.orig.tar.xz ab53fe175c40429bcd0aae4e4adc0bcf60e51756c5dd26c8a55c3f356d8dc574 145968 graphicsmagick_1.4+really1.3.35+hg16296-1.debian.tar.xz Files: d027337a690e576f5a311c4a961b74fe 2952 graphics optional graphicsmagick_1.4+really1.3.35+hg16296-1.dsc d721311761690c11d521399303aeeebf 6029156 graphics optional graphicsmagick_1.4+really1.3.35+hg16296.orig.tar.xz 6289d1aa9ec8858a3be563d6c5479f6e 145968 graphics optional graphicsmagick_1.4+really1.3.35+hg16296-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAl7X0AIACgkQ3OMQ54ZM yL+UNw//djz+wQlxYKlWtCGGXKoJ0GZS3zHLppBZuknWlxpJlupdql3eZGLlCPS7 lGKPgyA9rSGxsdMUX2LMdds6IEFkM3mC58tX8/E3Bs7jZiWXz7nDJKNIiDjt0zL/ HQRISZUol/6dmHTQByFr/a/17Uk3BBKcDcgJx7CgcKSw1BrNb9dQqYd6T0Dzys+h urS2DsTXXYKDixnvQJWDrsUEejHm9HdB3HW4yBtJpHuPpaC/2dahlC7tduPK+7YD WhXBP5RUmgwiFOQKkxXCgrWxajfS2VH41CibntMiqcNx6ml8/EKgl9d9X27aBszt 3LkW+3qj02XizsJI4JfJuc1Tnh/ld3G+JDoCBHz6hDrQzN5TU7Gt7xu8nH/KYZsr hdkMmqpyDUH2BBgElsDRFBWTOErri7x7vNEW1Mpi20cC+vGPKASeZWhJ5wqghgdG QHWSaQE/o8YD5nsPEOB0TkavNacAuQR7frYcSgkAcwbpYhIyKVI8iFd55xR1k4n7 aczeTptBycJaMnIz9QcwhUSuaO+zmyrLhnGLiLHKZj+UR/PQb71mOgh3t4yJTekg g20o5cI+yR+BIEWo8oH5ZnsNuEARF385zCHVBHNpe/rwj9WPr8x+JV4aZCqfyRkB LvJv3mPXr63ds9QewGddSE38qPoCBUXldcz41xnJlfLFE0gEE54= =EM8x -----END PGP SIGNATURE-----