-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Jul 2021 19:03:02 +0200 Source: aspell Binary: aspell aspell-doc libaspell15 libaspell-dev libpspell-dev Architecture: source amd64 all Version: 0.60.7~20110707-3+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Brian Nelson <pyro@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: aspell - GNU Aspell spell-checker aspell-doc - Documentation for GNU Aspell spell-checker libaspell-dev - Development files for applications with GNU Aspell support libaspell15 - GNU Aspell spell-checker runtime library libpspell-dev - Development files for applications with pspell support Changes: aspell (0.60.7~20110707-3+deb9u1) stretch-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2019-25051 objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow * CVE-2019-17544 It was discovered that Aspell incorrectly handled certain inputs which leads to a stack-based buffer over-read. An attacker could potentially access sensitive information. Checksums-Sha1: eded0650d297bdd1e859c7987969511f02b9b539 2446 aspell_0.60.7~20110707-3+deb9u1.dsc b5a41b92d70740efe7785baaefe1616c69c34637 1876992 aspell_0.60.7~20110707.orig.tar.gz a3843dcd19cb5d9457f15252e386c814d0482a5b 26536 aspell_0.60.7~20110707-3+deb9u1.debian.tar.xz bca2f9bd8ed61154d4190d8c81ed5a11347b05dd 422890 aspell-dbgsym_0.60.7~20110707-3+deb9u1_amd64.deb d78e98e9f1d2661b1219f8e1891e11ef25ace008 259830 aspell-doc_0.60.7~20110707-3+deb9u1_all.deb 2999a2d6eecde25ccf4fec1283a87d36b7d3d032 8332 aspell_0.60.7~20110707-3+deb9u1_amd64.buildinfo 3c417c58cae7510f566120dd03a4ccf1059b50c0 226762 aspell_0.60.7~20110707-3+deb9u1_amd64.deb 747d0cc0fc104290485890d242796a7b521c0d6a 40380 libaspell-dev_0.60.7~20110707-3+deb9u1_amd64.deb 25db1334e60740adaaefb81961c4f2431e863f17 2146076 libaspell15-dbgsym_0.60.7~20110707-3+deb9u1_amd64.deb 9d91376cbea64050ca8b0f3b9b72763dc78c7d14 330984 libaspell15_0.60.7~20110707-3+deb9u1_amd64.deb f744bdf54255eff6fc12e7a47802491e4cbe3a8a 37446 libpspell-dev_0.60.7~20110707-3+deb9u1_amd64.deb Checksums-Sha256: b992f72312b9888d010c0a16a2ef436d34f318adf349a3f4fdab6c6df2c4eef6 2446 aspell_0.60.7~20110707-3+deb9u1.dsc 71a41224e224af08a0051a9048fc0b4a912acee997d4870cfd68bd7327c45b61 1876992 aspell_0.60.7~20110707.orig.tar.gz d5d7eae7add09007060d0afbab43a636228c0f1d806299d96427398abd93ffda 26536 aspell_0.60.7~20110707-3+deb9u1.debian.tar.xz 3f61a1101e2ab0cc3d4a36a2d893212a34f4f3e2181caf6731899ec2cd5b4241 422890 aspell-dbgsym_0.60.7~20110707-3+deb9u1_amd64.deb d95f3336a8cc6f1c132d574add553596c934e2bb528242531159e15dc20caf4b 259830 aspell-doc_0.60.7~20110707-3+deb9u1_all.deb 3dd91f918798b0dc9fd90ef84b579cd4c35f6a3003406a2faaa180b42ecc70a4 8332 aspell_0.60.7~20110707-3+deb9u1_amd64.buildinfo a7f154ed7d9e5403261d370b6e49282afa45ea66540023e6f650a362b9e45899 226762 aspell_0.60.7~20110707-3+deb9u1_amd64.deb b78507d3dce28b9ee6edb62ba0cd4df44d7d1aa0ec550f603e152cdb4b45a16e 40380 libaspell-dev_0.60.7~20110707-3+deb9u1_amd64.deb 62b94ae27489724002c713457855fb96acae87c54a5413508b4875c1b9c4675c 2146076 libaspell15-dbgsym_0.60.7~20110707-3+deb9u1_amd64.deb 2d2325734bd88a29c140bf1ca85985a3e4016859229d4605a926caa3a40ae99c 330984 libaspell15_0.60.7~20110707-3+deb9u1_amd64.deb 300ad29641a7788f57cb4a20e439ae4a9de69b1fc0ffc9199a8f4670ed641b30 37446 libpspell-dev_0.60.7~20110707-3+deb9u1_amd64.deb Files: cd6bd471cc5f612e67fb6d6b75badc79 2446 text optional aspell_0.60.7~20110707-3+deb9u1.dsc 9a80faddad3222b88c544e93d2ab9579 1876992 text optional aspell_0.60.7~20110707.orig.tar.gz f60e2d28887c4e8f1be18bfcba4298d4 26536 text optional aspell_0.60.7~20110707-3+deb9u1.debian.tar.xz 9472d28dbaa6187a9d3103cda4736bc8 422890 debug extra aspell-dbgsym_0.60.7~20110707-3+deb9u1_amd64.deb 27421d79648e4e76d30680fa1af3373f 259830 doc optional aspell-doc_0.60.7~20110707-3+deb9u1_all.deb 0bc9ed25460b29996a98f546b314bd86 8332 text optional aspell_0.60.7~20110707-3+deb9u1_amd64.buildinfo d4c9bd6648f2f6195ed190c811020218 226762 text optional aspell_0.60.7~20110707-3+deb9u1_amd64.deb 2573c4f2ed85e1517c723538826eeb5f 40380 libdevel optional libaspell-dev_0.60.7~20110707-3+deb9u1_amd64.deb 79bd8417b911be22906b7b94de60a0e2 2146076 debug extra libaspell15-dbgsym_0.60.7~20110707-3+deb9u1_amd64.deb 66d972f5d7d10e59af8041e02d05a2cb 330984 libs optional libaspell15_0.60.7~20110707-3+deb9u1_amd64.deb 2940eb3e7d36067a17358c91a3284b9a 37446 libdevel optional libpspell-dev_0.60.7~20110707-3+deb9u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmD92dxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYRzHnEACTBQJVubMwuqwWQ03mA5QtVDKSvlqt FNnJ87DkqDIxploe9rx0t0IhtK8paHzMUd8GuD8yl2Vh8IsOthM7aUc67EaVmaQ/ J1plGhWMsNQW5avlU6IfkJ8VbOSIP5KgiPtjvacgf/rm2EJAssvCgtLRX0QP4WY3 4ci2oU0CBxh4rlYPR2oWXuXzpJjE0iBR/Y0UyX3nYVHhtk0zr3+DWZ7jef3GIvQU GmoOKz5CpHduXHbs8htB9KlqhNsksGePJdfSaqRztLXmB5XNIamHlV1yVJsOZmf7 YDX8sr+Of92WAHSG54zihMV21B6yT6SPBX84+Si2DTfV5T00+8GULxpPQutVw61+ LW5rhJL0bd1L9kX4f2rEahOWEb3NXXeAxK5fTafPgSutKrE8orui4jfJdydJJulZ N6C8fa6YWtb745d5v8bvLPM6Znl3NU7c7hQF69irs+8tOEpYwoSETs0gdaxt5rbL s5H5QxmBsQXmrrswd+rSAZaeN8+3FODfXJt45wkXKz7CNO0xZ+6KFCSh7BLObt09 WGPJD66BcVxaxoUaWfvaVkl+lE0oPcFcXYNGRPc9m+rh+iso8P63ebJoMoa2nwB0 QHE4i4rUY7VteEy3n+uPyyXDmzoE2kaBcLCBQfIO3b7RskwD4R6crx07H3AQMp8F nqSeCfu2ObiYcg== =03JZ -----END PGP SIGNATURE-----