-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 14 Sep 2020 09:15:20 -0300 Source: qtbase-opensource-src Architecture: source Version: 5.11.3+dfsg1-1+deb10u4 Distribution: buster Urgency: medium Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org> Changed-By: Lisandro Damián Nicanor Pérez Meyer <lisandro@debian.org> Closes: 961293 968444 Changes: qtbase-opensource-src (5.11.3+dfsg1-1+deb10u4) buster; urgency=medium . [ Dmitry Shachnev ] * Backport upstream patch to fix buffer overflow in XBM parser (CVE-2020-17507, closes: #968444). . [ Lisandro Damián Nicanor Pérez Meyer ] * Backport XCB_Fix_clipboard_breaking_when_timer_wraps_after_50_days.patch (Closes: #961293). Thanks Nicolás for pointing us to the bug fix. Checksums-Sha1: 57b3848aa0b18f73752389c182019c65a5f158ee 5206 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4.dsc b61d53bf3238476b24e246d8c51def0076163549 244416 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4.debian.tar.xz 21b1187a1d22e2e2d27d64499419e693ad4b247c 10690 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4_source.buildinfo Checksums-Sha256: 68d2c3c114cecd6e18b68650d02acc954a31f709a0b9dec4c4df98811b2f20a0 5206 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4.dsc 2742b480117f231a585ec352f25929c942ae7b443acfd615b696094cc750d4c6 244416 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4.debian.tar.xz 52c9eda66d9dd176207de3bde0ff7abe3c46f3eee1d9b544bb47c12faf569e7c 10690 qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4_source.buildinfo Files: b73f79d8b78419cb8ddfcb2c8aa85c8f 5206 libs optional qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4.dsc a41405c96203d67fc10bbd5e92612428 244416 libs optional qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4.debian.tar.xz f9c2f2912d9cd3c152e3fb3fb59afa8b 10690 libs optional qtbase-opensource-src_5.11.3+dfsg1-1+deb10u4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEEt36hKwjsrvwSzE8q2RfQGKGp9AFAl9fZEEUHGxpc2FuZHJv QGRlYmlhbi5vcmcACgkQq2RfQGKGp9CznxAApquPOyu84JKJRFDy7ZevdY86WIYK rOUFKJ8c2AIdVZ7drwNT3b7hAh4Na5XV8QBaMfwjbBnVtQMoB59jnrOjubyLv6YW OZCtXpr7pOQqshNWXGLeyJ7qf2KNNrYBEaXWWPsCLcyjCAcgZabx2avtm2s5XBL7 kOHZdFzgsJNnfRp/VMTuqlgAxwKz/6EjVhhAlbu4z2nV2Ry+gryr7nPMZ9/3vouR Qpxcq8FQbG2p9snsqKn25BCxJUAm07DfG3Mwf3ijUi51hRiOXHN+85nwUfksSwM8 zymscmYUAAOGl9LLnnV4vMvkLUglheyIp9ANPuK+s0LFcxptgau4jn6IDz3tyLiF fNYXjXp6IYsgXC9qSa4HvFCKdf1TsFt74UwRQyHUpvCAHdtr43jRMx8fFXNMLYKh /2QOy6xCw9FRt0NEi797gvxCIO/B+S/PKvaDWzP2IGOFP/S4T+hpHz9LaNhUcUO2 qK4ZmVcT7rxiFZWhJMXjkAUkfEiYKJmS/cgL0BYuAqFTd5vu6pzqFKVKTfESDHaA A7tCRqYlFdc5r1lPYkuXq6X5992wcMMz/LD/29d4/WNdyBj5RJbMgOqklNnAnFB5 Lyv/LAScBRtMCsVzAyYzdX81hoMu72ywFh+5wdFzPWk0p8BFmOauR8uQinLpBfHI 0tsccpl/wxCWS7E= =rJJ0 -----END PGP SIGNATURE-----