-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 09 Jan 2022 16:26:35 +0300 Source: qtsvg-opensource-src Architecture: source Version: 5.15.2-4 Distribution: unstable Urgency: medium Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org> Changed-By: Dmitry Shachnev <mitya57@debian.org> Closes: 1002991 Changes: qtsvg-opensource-src (5.15.2-4) unstable; urgency=medium . * Backport upstream commit to do stricter error checking when parsing path nodes (CVE-2021-45930, closes: #1002991). * Backport upstream commit to reject oversize SVGs as corrupt. * Bump Standards-Version to 4.6.0, no changes needed. Checksums-Sha1: 1e4a7fc4e58555075520b5588a2bedbab262d0c7 2901 qtsvg-opensource-src_5.15.2-4.dsc 3c9b42bccf1cc24647fcc9c484b1417550b3b9cd 14188 qtsvg-opensource-src_5.15.2-4.debian.tar.xz 5563b3cc5d31d91c478bdd485c32f7b2e83ef14f 12575 qtsvg-opensource-src_5.15.2-4_source.buildinfo Checksums-Sha256: 6e4f433a981d20f9484933858866e5f0e69b291c50fff7c179f76ed23ae6cc58 2901 qtsvg-opensource-src_5.15.2-4.dsc 3e55ebb6eb48953dc17526c37634c7fe90188e338dfb59b2512f73a9e42cae4f 14188 qtsvg-opensource-src_5.15.2-4.debian.tar.xz 70a883b5031ca29166754b82b16a21bd90041875d1485a854c405072b5a85b80 12575 qtsvg-opensource-src_5.15.2-4_source.buildinfo Files: 2892337417aa8db9016326d841bc21d0 2901 libs optional qtsvg-opensource-src_5.15.2-4.dsc 19c695c70b8585ecd35f53b75adde8d0 14188 libs optional qtsvg-opensource-src_5.15.2-4.debian.tar.xz 1a99beab02be94c2c99605e685facb98 12575 libs optional qtsvg-opensource-src_5.15.2-4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCgAxFiEE5688gqe4PSusUZcLZkYmW1hrg8sFAmHa4xETHG1pdHlhNTdA ZGViaWFuLm9yZwAKCRBmRiZbWGuDy7WeEACg+b7MBOOVYzZ/0NLAMfFcZ/M430dN 09ZOkdcJf5A5vMyJt7kCoEYVtojplG77S3FmIBXvUXgmjMANZu0KnULLnyZhHLoh nc9WGa6t2/3zS67bs2PPTt7qQbDTo7LHl2+u/UuBhR3nD7JZnoNP/0nWC52xzlH2 f908jZRWe8BvY6Dbkc9uqCUGLAp9pSsqAXLr1hEDsSn27IGN6LMwwLVjqIDb80ks YDZxihW7RUMQsPEKQ5f2RET9L5yB/zf/jDYcEPnIasA7x3R0NCs/+ZvtvULSwYki c0de4yl5XOlse2Te6/VLGWZnAoDSRYyG5UNbbpFkvF+iKKYxleDBsADRx3XWJqKe InjbzSzoRj+KblGKuyOwW0CeccAsrxc27dLSOjf0BJ1GSrOuow00Q3XWn39ugVIF YpByFNIF8g5HjaRZVZNPnMLdwcmg2ANZCm65CeI/T2pNc72U8bTT1lXOAa9f6dG3 fsA/pyu1JlCLo3NqxLS4oUxjixO7SAEPbDuNQS1Ev6nwEf2jIGpSWP4uxxMgpu/3 G5MzvepPciuLCK3v0vz4eivrei4/QlVElS1p2LkM3Kdga0/RUa+BpFmRuZJLViIV G+HwVN/hZCPcxTFzJhIYsvX1KvAMVWGRFah8Vg782zLPMZZ+oi6ry3Txu9hfHyHV kWM2C/PxBCoVfQ== =IDXB -----END PGP SIGNATURE-----