-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 13 Jun 2020 18:39:39 +1000 Source: libexif Binary: libexif-dev libexif12 Architecture: source amd64 Version: 0.6.21-2+deb8u4 Distribution: jessie-security Urgency: high Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org> Changed-By: Hugh McMaster <hugh.mcmaster@outlook.com> Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Closes: 962345 Changes: libexif (0.6.21-2+deb8u4) jessie-security; urgency=high . * Add upstream patches to fix two security issues: - Fix a buffer read overflow in exif_entry_get_value() (CVE-2020-0182). - Fix an unsigned integer overflow in libexif/exif-data.c (CVE-2020-0198) (Closes: #962345). Checksums-Sha1: fda1f66501649f5eabb9549b06f28165bda3ab8d 2098 libexif_0.6.21-2+deb8u4.dsc 4106f02eb5f075da4594769b04c87f59e9f3b931 2081615 libexif_0.6.21.orig.tar.gz 4130e915e36de454328c3e1ef934ce3553e3cb9d 16732 libexif_0.6.21-2+deb8u4.debian.tar.xz f2e76ed06951fa4011207d5d2b53c5e1bc04b7ae 398766 libexif-dev_0.6.21-2+deb8u4_amd64.deb 1d6d0b3c35eca6f5fcfcdf1789bc8b3038612dae 325328 libexif12_0.6.21-2+deb8u4_amd64.deb Checksums-Sha256: 0551ba7f793ca4d9c7846323a96321e65fbf0bb6720e704e29eb1b2962363b97 2098 libexif_0.6.21-2+deb8u4.dsc edb7eb13664cf950a6edd132b75e99afe61c5effe2f16494e6d27bc404b287bf 2081615 libexif_0.6.21.orig.tar.gz b898554dc0736ac3b5bc2bef508eb1a3e714c4c0a43704995d30b15b99315a05 16732 libexif_0.6.21-2+deb8u4.debian.tar.xz 0af9cefbbab0c37a317e8e2d761ae5784af3734ba0b865787aa382be9057cfcb 398766 libexif-dev_0.6.21-2+deb8u4_amd64.deb 929f2b715d6c7a0bbc39339be1f3ba0c7fc91b1d1b38a8f00ccf2c2c2c4da65e 325328 libexif12_0.6.21-2+deb8u4_amd64.deb Files: 8d72b5b7506889d3f810486cf7dd27e3 2098 libs optional libexif_0.6.21-2+deb8u4.dsc 9321c409a3e588d4a99d63063ef4bbb7 2081615 libs optional libexif_0.6.21.orig.tar.gz 5ad5b4fe7139a1d195798f41a4ebb7dd 16732 libs optional libexif_0.6.21-2+deb8u4.debian.tar.xz eb416dda9f8011cf472d634e4e56d209 398766 libdevel optional libexif-dev_0.6.21-2+deb8u4_amd64.deb 3d73a5f009ba1ce08a05393e9fd2f125 325328 libs optional libexif12_0.6.21-2+deb8u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl7k64oACgkQgj6WdgbD S5bdng//UQSFgEJ1GgSI3M4/kSWKGFxQ0t1oYmQtOzRC3lthLpxbzppRGDsSMac/ XLH7YIPH2zwUwRCsnITV+lehwol4zFiUXPkyeRM2xASG3ZeOv/olXqfEkFGBXUNQ /StLKZaT4MUMFNYogLLlA+n99pzstFb+VJG159OjxHPtMr2hPznz8S074spgl2On Y4Yx5BVSHQGEL2cWLGuOXjlGm886A/+Od8nuT7Z8XrqWQv7aYZf9Ye94yPDMSmLk aUbsoWCPsMXK75D7zbtX6gl8nbUls+boRIXcD1uJ9XJUiGBmn4V7hmSKIHl5Yb2v qFqowMRhxhI6OZI1LD+C5ByXTT9nMZW8AMPdwee1dzWMZXzHYBFPRhdtshSZAOlv eXn4WJFA2fN3Cr3N37vZpjt7uSYYon0qxAkF8mHY9PpDJ70gztcvs2Y0fCazNYhe NnpAYUF6tYC4QWMLnUHUD4GhDt5RPZdhoq1JT15xaVILUQGIGTOEEsj1mAYYa7Q3 3uiT8wDva1jVgisQocihRC0+EOqqZnI1ZVEJdh/SJGMfYP2sK322ZwLYTZFMgZ9o UGqE0bb6H6ZqYcrrtWVNiU5xuimnDdhFdrXGTD3mW3WWGwQyCJRMv8upCjAgB+Ei 3T1rA79Jn2I2Ra0nU47qbpz+gl0GieigZm/feJskveXgMWdgaCc= =BrEN -----END PGP SIGNATURE-----