-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 13 Dec 2020 15:17:50 +0000 Source: openexr Binary: openexr openexr-doc libopenexr-dev libopenexr22 Architecture: source amd64 all Version: 2.2.0-11+deb9u2 Distribution: stretch-security Urgency: high Maintainer: Debian PhotoTools Maintainers <pkg-phototools-devel@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: libopenexr-dev - development files for the OpenEXR image library libopenexr22 - runtime files for the OpenEXR image library openexr - command-line tools for the OpenEXR image format openexr-doc - documentation and examples for the OpenEXR image format Changes: openexr (2.2.0-11+deb9u2) stretch-security; urgency=high . * CVE-2020-16588: Prevent a null-pointer deference issue in generatePreview. * CVE-2020-16589: Prevent a heap-based buffer overflow issue in writeTileData. Checksums-Sha1: 56a6e208fe4b03da1574b64cd591bae2a1453c7b 2308 openexr_2.2.0-11+deb9u2.dsc d09a68c4443b7a12a0484c073adaef348b44cb92 14489661 openexr_2.2.0.orig.tar.gz 0fa9b5ec6cb24165739bb989064f195460eff296 28344 openexr_2.2.0-11+deb9u2.debian.tar.xz 84e4a350704ef3b0f7a4420b64e6a359d6b87155 703584 libopenexr-dev_2.2.0-11+deb9u2_amd64.deb 15155b57284e9a6af1659ad03aae53a44315e759 3875296 libopenexr22-dbgsym_2.2.0-11+deb9u2_amd64.deb ee7c1370876c3fdb2a6931d464d466881f3f3c89 585370 libopenexr22_2.2.0-11+deb9u2_amd64.deb ea354fe5021c72b32083c2f4686e04abbe67bb27 655430 openexr-dbgsym_2.2.0-11+deb9u2_amd64.deb 856bab43b9748cdd96d398e574b99b863e76519e 2324608 openexr-doc_2.2.0-11+deb9u2_all.deb 165d8a09ac25ce6835c5fa27eb73239938ad354a 7385 openexr_2.2.0-11+deb9u2_amd64.buildinfo 8d1c94dfd2483ffeee4c9c39b56917cbd566dc3f 85354 openexr_2.2.0-11+deb9u2_amd64.deb Checksums-Sha256: 928aa0719a3c9a43e4efc648164bf77bb708d5672e95e8ba6a90593ae5cc082d 2308 openexr_2.2.0-11+deb9u2.dsc 36a012f6c43213f840ce29a8b182700f6cf6b214bea0d5735594136b44914231 14489661 openexr_2.2.0.orig.tar.gz 01e7b232fc8280951fad4bc20172d95219d7f69b71893dc60fa612474d2594a8 28344 openexr_2.2.0-11+deb9u2.debian.tar.xz 77871d70d64e6bbed33cf94ef5af1584c344b53c8947eaa87bd98c870c4d1b12 703584 libopenexr-dev_2.2.0-11+deb9u2_amd64.deb 0e6d6fcf3b6bad69900cde8f9a043a8f4fad1c72f8227dec1dba02edfb25da1e 3875296 libopenexr22-dbgsym_2.2.0-11+deb9u2_amd64.deb a4910f04ba63a5db20276e66a53b755d5bf7fb8a4b8090e236dbad2dbbf6cdbc 585370 libopenexr22_2.2.0-11+deb9u2_amd64.deb 91992c5a7dda4cf8f22968c5f02fa4637d4a1e0418a295373152c1276942ec23 655430 openexr-dbgsym_2.2.0-11+deb9u2_amd64.deb beb80b0479cf991c1edbc577f47398c317b81d501218acc16387c3728fe55479 2324608 openexr-doc_2.2.0-11+deb9u2_all.deb 4ba9e2f6f8a2fd246e7ffe6d921752ed78dcaa60c82fd7bf5479262aefab7894 7385 openexr_2.2.0-11+deb9u2_amd64.buildinfo 7270f16f4e991be99d86d4f5cf29c798e2ef54d7b2143a7416fcd444cea88bf0 85354 openexr_2.2.0-11+deb9u2_amd64.deb Files: 55755e2909975c57df572c723dd08c2c 2308 graphics optional openexr_2.2.0-11+deb9u2.dsc b64e931c82aa3790329c21418373db4e 14489661 graphics optional openexr_2.2.0.orig.tar.gz ef3e27625bf9617250f57cd61cda4c10 28344 graphics optional openexr_2.2.0-11+deb9u2.debian.tar.xz c94cba3c9490311ff9a209e10a3d0865 703584 libdevel optional libopenexr-dev_2.2.0-11+deb9u2_amd64.deb 931a73bb560dffdf48e5b8b07623b4cc 3875296 debug extra libopenexr22-dbgsym_2.2.0-11+deb9u2_amd64.deb e248e5377fbc6a394ae2fada92f0d0fc 585370 libs optional libopenexr22_2.2.0-11+deb9u2_amd64.deb ecdb3a68eac65c13c789462e042a4a6b 655430 debug extra openexr-dbgsym_2.2.0-11+deb9u2_amd64.deb 4610284a8630fa9bc90befc5a6d2d5d7 2324608 doc optional openexr-doc_2.2.0-11+deb9u2_all.deb 5d1691164f937365effb27a2549554c4 7385 graphics optional openexr_2.2.0-11+deb9u2_amd64.buildinfo 8297d55c8cfbb7c18cf26d1e580e3e99 85354 graphics optional openexr_2.2.0-11+deb9u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl/WM4QACgkQHpU+J9Qx HlhbtxAAtfOl4DcQDrFpeMvzGAumF6pkPsED42EY2W+yF8xBw7f2UtCM90tRYFN9 L+2arWlZk/+LOLvkmlm3AKi4VW83AbDQ8Q7LkuCnHJ0k9GszIU98jwAczz9ljjaA vocCfsa4rpT4zObruEgzzwG/o8zUXbM6C7B6W9ROWeD3f3WeQj2Os/+P5+KmRnJ/ +4gy48P8QmfBjqn8HP3yJ5zcUAXuq/LMpGNetKdSRpfk+DXGr+z7euXMViLgWh4I M7hkIFdNlf4Ok2tlJpVW00zmXKWzem2SQzXY6z1YCSvHJTaxUD9VIgLmVQ/eog4r cgDbdvqyTAvSHiZPNfc1/lTe2pvUMwzTDj2+c+MGKpBuvEsjDgVjVQSeR1gWW2Hi S41XMRhB5w0guuH5LQiSoObMXtj6aavJu/taZXQN0SDIhgOpzEonxBv2iAVt1eye NOj76SBF56eSyXuVXmwnLmTjuSjCTcZZAjkSt0BohX7Attx4rtoBcnROktA1kUtz b7O5cIw5WFLfKfRam/iFa6EfRxoE3ceUeLZbugrEyuNtz5W0bFGQUQkiwpeMiA+p QYWYW9RBKM42bwskbXWKZpgUpgeg2hZESf8p4zZO5esPJDDwA94zFAKVfrbqUCrh 8PND8CfwAIAdjfSErgaBgKgcTYfnOiXKnrOeL7RU3SLp+0qbTSE= =3XyK -----END PGP SIGNATURE-----