-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 30 Aug 2020 20:26:04 +0300 Source: openexr Binary: openexr openexr-doc libopenexr-dev libopenexr22 Architecture: source Version: 2.2.0-11+deb9u1 Distribution: stretch-security Urgency: medium Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org> Changed-By: Adrian Bunk <bunk@debian.org> Description: libopenexr-dev - development files for the OpenEXR image library libopenexr22 - runtime files for the OpenEXR image library openexr - command-line tools for the OpenEXR image format openexr-doc - documentation and examples for the OpenEXR image format Changes: openexr (2.2.0-11+deb9u1) stretch-security; urgency=medium . * Non-maintainer upload by the LTS team. * CVE-2017-9110, CVE-2017-9111, CVE-2017-9112, CVE-2017-9113, CVE-2017-9114, CVE-2017-9115, CVE-2017-9116, CVE-2017-12596, CVE-2020-11758, CVE-2020-11759, CVE-2020-11760, CVE-2020-11761, CVE-2020-11762, CVE-2020-11763, CVE-2020-11764, CVE-2020-11765, CVE-2020-15305, CVE-2020-15306: Various security issues which could result in denial of service and potentially the execution of arbitrary code when processing malformed EXR image files. Checksums-Sha1: 9e5413440aa88f5e8a1ea867f95014678e4e62f2 2308 openexr_2.2.0-11+deb9u1.dsc d09a68c4443b7a12a0484c073adaef348b44cb92 14489661 openexr_2.2.0.orig.tar.gz 839c93ca6da84fc45247096991bea8100b409a1c 28044 openexr_2.2.0-11+deb9u1.debian.tar.xz Checksums-Sha256: cc1eddd927833dc4e9b896414f30c82da8d3b2dafa8520a9c59921aec1aefa6f 2308 openexr_2.2.0-11+deb9u1.dsc 36a012f6c43213f840ce29a8b182700f6cf6b214bea0d5735594136b44914231 14489661 openexr_2.2.0.orig.tar.gz 7122327fdf668a2ef74abeae709a7fa92a005ea9058a64e3bffe6450b0aab0ce 28044 openexr_2.2.0-11+deb9u1.debian.tar.xz Files: d1db6a6cecfe9878e6c36b388bc8bc23 2308 graphics optional openexr_2.2.0-11+deb9u1.dsc b64e931c82aa3790329c21418373db4e 14489661 graphics optional openexr_2.2.0.orig.tar.gz a9a01fd18163a2e1661c7b0faafd49e5 28044 graphics optional openexr_2.2.0-11+deb9u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAl9L8E0ACgkQiNJCh6LY mLFV2Q/+MIl9nqwBvF4HbfcOPv7XBWraOf5M6QAtRpCv5AeiF+N3ZD8nzIZ9XnMQ dlFfgE7AxQHQum3YxO3bfwtHPRpbVU9ePVEQIzYWgZeAYwnwS7YN+4+n15bfldj1 KHjnFTs2l1hzgeVQiFfgxt4MvVuQsd4JZg56phCGXjGl/MuvOwh7JJSY5oYp+jTi UY1Mae6O3euXHisySKpJ7U68DyWiNy8vvtmlloroedFiCWRRWHOoIrePrm+lFj8M F6KlAcZJAQUdlpqoUWvVzll3TGI6kOEunHmXmJlkaamwV0g9R7u0MXoP36lVVjCJ YjZFuUwyPArQAF9z7NOn32Kc5fXCnMU1+kSfcLHcGeDjksOG3MHkzxvelabwuK0r Ppsm16cI3WBm8CfaF9Rjtn8yibBckSbAMkWT5z+ADgYtBLUGsejEws1g8bU70lk9 rfTwhoyB33aq3mJJKYUImQLqgU81PE8eA5ND4se1K2ewVFnJnnrGOlso5/CY6YgK TiajjnPlmJ+Wxl9Rb7ZE/SQFzIkvGC2UkBrW4NVJSS7aJL7UXoRWcGcDx2j6K/JI mIXsih+oUPSdEUR+aYMdQTJvQ4iWyLriGlBSFaU4z+0/cJOzUXpKMiR/vh6CnwrA tKVgQAzSyDxIavwiDssLR6X+WCqLFEttSU+oaY35kGme4sWTIfs= =jZAG -----END PGP SIGNATURE-----