-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 28 Nov 2021 17:12:50 +0300 Source: qtbase-opensource-src Architecture: source Version: 5.15.2+dfsg-14 Distribution: unstable Urgency: medium Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org> Changed-By: Dmitry Shachnev <mitya57@debian.org> Changes: qtbase-opensource-src (5.15.2+dfsg-14) unstable; urgency=medium . * Backport four upstream commits to fix massive memory consumption when rendering specially crafted SVG files (CVE-2021-38593, LP: #1950193). * Update symbols files from buildds’ logs. * Override some source-is-missing and unpack-message-for-orig warnings. Checksums-Sha1: 9078499375ab96d1914e9df42ec81f3d425b09bc 5483 qtbase-opensource-src_5.15.2+dfsg-14.dsc f6d40df4ce0a222aacd27a4cdb7191f27a6edbff 267160 qtbase-opensource-src_5.15.2+dfsg-14.debian.tar.xz 3c1744c1ec3124cdaa0a20190eb9587cf3a53b04 17699 qtbase-opensource-src_5.15.2+dfsg-14_source.buildinfo Checksums-Sha256: c9e4092c3108223f0985e9fa114d5c78e72dcdfcd6b9ffcaafb2ded9fd19988b 5483 qtbase-opensource-src_5.15.2+dfsg-14.dsc c3a658b853837a6656ce9fc43a00d5dec0f8b1db6ddccd84875a9f31517ca5c7 267160 qtbase-opensource-src_5.15.2+dfsg-14.debian.tar.xz 288617e0fbe854e9507dbeab965b054a5f298f64e5e584b95becfebfeaedc279 17699 qtbase-opensource-src_5.15.2+dfsg-14_source.buildinfo Files: 7975710f30675b42d11ff63761b67aca 5483 libs optional qtbase-opensource-src_5.15.2+dfsg-14.dsc c1362f4ac4a8e038080e7adb35af83e2 267160 libs optional qtbase-opensource-src_5.15.2+dfsg-14.debian.tar.xz 61e81cef333abcc088b15c2b05e5feb6 17699 libs optional qtbase-opensource-src_5.15.2+dfsg-14_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCgAxFiEE5688gqe4PSusUZcLZkYmW1hrg8sFAmGjlbQTHG1pdHlhNTdA ZGViaWFuLm9yZwAKCRBmRiZbWGuDy4A3D/9K3Pt7AcFU9wOxykC2hKchuoJNkYw4 GmqRyGSyK4ROfKDKNhrVGD847i51hFcWRmEnORPfblYhuhv+Z4dbw80ORXnKdsoj a5XlrRiXqmFb2dyL4Wxw0uWo98DzKzRjjUF9Wxm/V4e/8AbjpXoh0Ja0xOWZmLK1 RehGS4VEmW7w+lPGy8amC3X6yt2Fck8cYhshsA6iT3r5StbtgcT7JFJoJRuT+mN2 kkeoCg8lr97QoPW4AZX5frgx1uEs1iBo9Ci/7JI7y8RcHEUpCKsKUjQvFD+1X8P0 GI9UWNJAEldarWX/iGpC++b4IKAqqN1D/rE+pAYoOAm7kFfJ78jGpI7lQ3BXJ7m5 jOiRqsR1NPghUup1yP00K+rUsgktLaWNoT06gBvsLHqqo4vVp68ayMfhF5HCICKi BKJ1Ksr2aiy7Roqrh5kuaxZemxYpN5KFx2Ylk+HxSbt0GGoUmdPsjZ8xqZ4mNaES HmgUo8Mmho1JqCXpRcWfR2uF+SwQ0iQhZOws+e+P3Xpp4+pDkoFwCsMQL+NHhPXd PeyKJuT3J7mBnL7+xwVgosyF++KgDbibl1WBWAHfl5VrotqwlkURQezs03z/bcSc KaJRaaViCioIUtpm3L/BWNKacqUx6l8ji0Un79NJ85NYJN3NO/K4SG6gDT9IevQy vhfbvGC0XFVlvg== =Hcm8 -----END PGP SIGNATURE-----