-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 06 Jul 2021 21:49:21 +0200 Source: scilab Architecture: source Version: 5.5.2-4+deb9u1 Distribution: stretch-security Urgency: medium Maintainer: Debian Science Team <debian-science-maintainers@lists.alioth.debian.org> Changed-By: Anton Gladky <gladk@debian.org> Changes: scilab (5.5.2-4+deb9u1) stretch-security; urgency=medium . * Non-maintainer upload by the LTS Security Team. * CVE-2021-31598: Out-of-bounds write in ezxml_decode() leading to heap corruption * CVE-2021-31347, CVE-2021-31348: incorrect memory handling in ezxml_parse_str() leading to out-of-bounds read * CVE-2021-31229: Out-of-bounds write in ezxml_internal_dtd() leading to out-of-bounds write of a one byte constant * CVE-2021-30485: incorrect memory handling, leading to a NULL pointer dereference in ezxml_internal_dtd() Checksums-Sha1: 96bafcb61f2622e901213891d286eb8409a4d060 4015 scilab_5.5.2-4+deb9u1.dsc 93057510f2b9089f39c557f45821146c1f6923b7 69626327 scilab_5.5.2.orig.tar.gz bbb9e25f762ef2273c67726445cded74b236240d 76340 scilab_5.5.2-4+deb9u1.debian.tar.xz d924a1ce7fd05f33d844e3dbabb6be0a12625a9f 13452 scilab_5.5.2-4+deb9u1_source.buildinfo Checksums-Sha256: ebc807e44a78b0d67c01c90dfe23d2cbc39a96e789f8d888696a61b77041fb12 4015 scilab_5.5.2-4+deb9u1.dsc a734519de96d35b8f081768a5584086e46db089ab11c021744897b22ec4d0f5e 69626327 scilab_5.5.2.orig.tar.gz 78cc7835382f577480ed5c939fafd317c8d19e3fae0c43811e9985cc7982c99c 76340 scilab_5.5.2-4+deb9u1.debian.tar.xz fa83a07708f031dcea21015ff12bf016c1b199880bc57cc29e0fc8242b4a11fc 13452 scilab_5.5.2-4+deb9u1_source.buildinfo Files: ce1ed3a42d998f497b784464892349b1 4015 math optional scilab_5.5.2-4+deb9u1.dsc b6fab39d76841f41ddf8cab927dea305 69626327 math optional scilab_5.5.2.orig.tar.gz 1128373460c351631797be63157b5499 76340 math optional scilab_5.5.2-4+deb9u1.debian.tar.xz ce7672e7454e61e57c523d4af2b229c4 13452 math optional scilab_5.5.2-4+deb9u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEu71F6oGKuG/2fnKF0+Fzg8+n/wYFAmDmA2AACgkQ0+Fzg8+n /wYhSg//b2sl/4k0syAdIg14jS5UgiONkuuLwGePunQG8oXso19pKgbpt9xgq8Os kV5i66fAOdc9HHjKGRLh0RDW7SVXbIcv/LzUpAh4rYeQ6WwBZX24qiQ/iYNK+M4M 8POFZNIzvxYMzcoqhopuW54Kj17GD/BAoC9p5jGorlCuMwtU5Mfl3TPttCImLseI omhgdeKGTFZ09JMTZYuaqk2wlDEaHfeuSzfXMSj1r/dEnj5MeVKrObwYH6bylyfc zTC8cDll6bxjdEq1TL9w/pUFBaLx3KqDX8JuHllNKv0o5nIszAtqBHJbYhjwFbQX 6OiPX0gSnytTrrV6/1nyCnRLS7DTY9PxZiknNNuan0WZ6qThye9gnOFklnGJUaTw uUlblu6Uvl7Tf2yVjDKciKoWORmegSQFeEhRQrnV1w7Ma7kX1S0Eu+bWXKA5/6ur GJlw4RP8ctawVhW2coQrDmO1wzxdpLfPB0QnPFdGgYRcPf4vMbH95Ww1lUgK6MM7 tLuJeRIYApwMiopAvrVrgZzimCPs/MYUgI3Xr/78Duf6K6vRzhSKHyD2zgBdRbIM dPgE6UtmUvqtodhbvCXyYnr/Tfesdio/Ft8Zj6P7VXcnewk6I9YqUBU9YddSGXzq MhGgIjucCI+NMHr+QJBYweBcz4B61xOJnvneNsimoN5VJCo6r9A= =zgi9 -----END PGP SIGNATURE-----