-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 22 Feb 2021 06:54:42 +0100 Source: graphicsmagick Architecture: source Version: 1.4+really1.3.36+hg16472-1 Distribution: unstable Urgency: high Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changes: graphicsmagick (1.4+really1.3.36+hg16472-1) unstable; urgency=high . * Mercurial snapshot, fixing the following security issues: - ReadJP2Image(): validate that file header is a format we expect Jasper to decode, - MSLPushImage(): only clone attributes if not null, - SVGStartElement(): reject impossibly small bounds and view_box width or height. Checksums-Sha1: 854aa3fe1e32a9593c2e698cda22ebcc54da6186 2916 graphicsmagick_1.4+really1.3.36+hg16472-1.dsc 2040fbbc4c692ff1c221805a40497a6e19ef8a74 5608172 graphicsmagick_1.4+really1.3.36+hg16472.orig.tar.xz 84e240a9138fb38da367d40b9328f9a8056ed457 148036 graphicsmagick_1.4+really1.3.36+hg16472-1.debian.tar.xz Checksums-Sha256: dee350377d98cb146b53d522d48e248c46d1f28c19f8a52407a52a9b29b51ecd 2916 graphicsmagick_1.4+really1.3.36+hg16472-1.dsc 60dc0ffeb614d177b01602872ef5f34d5332ef38626690e43bcc207e492f1866 5608172 graphicsmagick_1.4+really1.3.36+hg16472.orig.tar.xz bddd1189928a35bdb8b30c266b073e815afe0c23016df6b3eaa3cd9772f9a204 148036 graphicsmagick_1.4+really1.3.36+hg16472-1.debian.tar.xz Files: 824d6963fd48a22991ef6bf01b7fa3d2 2916 graphics optional graphicsmagick_1.4+really1.3.36+hg16472-1.dsc 7445b73a184d6b1abbdfb9f0b43fc0fe 5608172 graphics optional graphicsmagick_1.4+really1.3.36+hg16472.orig.tar.xz 19641bf604593d20598feae2436f90d6 148036 graphics optional graphicsmagick_1.4+really1.3.36+hg16472-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmAzTXkACgkQ3OMQ54ZM yL+erA/+KUKNcq6b2Yru7Zjdp1uP7dzNP4J5anBnwpNZThph3xOJi0UYVb2PovlV 5umAmtCFaZbcQZEHmoP7sovbeJfUMZzzMh7Y/6Bf8WWiR0xWSOJbrOeLu9fXCo2P cEzJ+mm2F7rWbtpmsHNfrUw1JyOA1on3OLAA8Ycq2fvdAPifkkEevIelcB08AUd1 aqwze0GzwCbm86mjEOeWzUO8kb0yJnb9fIBmYyej4aWUu9u3h2KqR2bz7CqXqOux DIQgQ3GtxPAZ9FFGdbWMy6BBlJOrYc1+yTOGVq8mknHGUD3xrVZSfgJyOElzjU5S zPFzKd+D5Yd23dlqJOyf7P8xlM+fiSWZYszgVnWKNxJVT+SXvouXRPpNGPiPzL3O xdFtqbJN+WciynlBaBfps/Jv+fGUcPHJ1XPuy+JFKLrFCoFofLK6WyxBuQbpV7N/ XpbwIdSBwdlYxIMXeezzAArP56/1CUCaArmQOsROBIlKLwmMdwoOY5CGON0qteRu jUVBgDzZ1e59tm0eh47BK+S6jRLIf1O9BgiL91A0d7EQUBMr4ldJ2CLh3dqkuXa3 zigZ4oZrChrmp5x1IBUQAFuGiv9UJa1hOdrawOE2AKDu0dNV0xll4Z/wFA1fYZpI yqKdt2xq+1bLpA7ttzDm34im6qPOG4yPrASs4Qu2ovCM5Kh71sU= =NnYX -----END PGP SIGNATURE-----