-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 26 Feb 2022 11:10:10 +0100 Source: pcf2bdf Architecture: source Version: 1.07-1 Distribution: unstable Urgency: medium Maintainer: Debian Fonts Task Force <pkg-fonts-devel@lists.alioth.debian.org> Changed-By: Jonas Smedegaard <dr@jones.dk> Changes: pcf2bdf (1.07-1) unstable; urgency=medium . [ upstream ] * new release + fix segmentation fault on invalid intput pcf CVE-2022-23319 + fix heap buffer overflow on invalid intput pcf CVE-2022-23318 . [ Jonas Smedegaard ] * update git-buildpackage config: + use DEP-14 branch names debian/latest upstream/latest (not master upstream) + add usage comment * update source helper script copyright-check * build-depend on xfonts-base Checksums-Sha1: 14dc1e61f4d7b8463f0bd4f1826e4ed6ec57f2b7 1908 pcf2bdf_1.07-1.dsc 72c696ebc06a305a39f74caf24d1f57084371d63 19104 pcf2bdf_1.07.orig.tar.gz 6da7e6f1f3f627358e806f021b05a746179b0456 4812 pcf2bdf_1.07-1.debian.tar.xz 195d95c151dc54f4e3b78c10fba44d2937d3b156 6197 pcf2bdf_1.07-1_amd64.buildinfo Checksums-Sha256: c82ed8976a5b6140322128b42ed758f0243ec790819968ba132e5ab13f30ef70 1908 pcf2bdf_1.07-1.dsc f2551a384387e15b0155efcb23c260261996034badc51ab43cfe27b8987cf4dd 19104 pcf2bdf_1.07.orig.tar.gz 13868f7ca339f6e0b46fb5d5cbb6682a9c8d14a7c3163e5745eb0ef4b4b8f633 4812 pcf2bdf_1.07-1.debian.tar.xz f658a16ef879c7b4934ee1c978f0a702d9f72b520a7ed6899e7fcd029795b4ce 6197 pcf2bdf_1.07-1_amd64.buildinfo Files: 58fe5913161baee53753af8b4e43c7c4 1908 x11 optional pcf2bdf_1.07-1.dsc 467f9b6b21a550c9d6d51ba00040b807 19104 x11 optional pcf2bdf_1.07.orig.tar.gz b8852beaf511abfa2cec92ee99cad317 4812 x11 optional pcf2bdf_1.07-1.debian.tar.xz aad4ce7f02fe3ee15d0a4c9fcd25fce5 6197 x11 optional pcf2bdf_1.07-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEn+Ppw2aRpp/1PMaELHwxRsGgASEFAmIZ/g4ACgkQLHwxRsGg ASHp0g//Xv+uEiDTC6PgRffF6JyEJwlWj2xCDs+gzfKrqrbPf2OvteJxBK9KD9L6 PKRry2ESdSXOx5XtKvkXdURdiDsNTJx0xxAlrq3W2OWLLHHPffrEId8TvhsTsmGf 4YPz9VqHZwR/xR1m34nAhmWa3FW41LRZN6q0qbsj0VcyHEqF8FfgdLG/b+cdYibt LCdh2PcoUqgoi2VKLQ7NoPFgXVUk/ke0KrpmZPMgQjsaEFYJflZJM/JLjHMTmlKm qkHq9EvmwtYZHd/xHNohLKR8FlWi0HDT4umjkv7D8gyP4vYS1LeT7mxJ42S9QEQr qiOKIp7X8KsGvcO/3WZAxrPNILYujt6nc/mPMcLMi6d8lBE6SZL1qrZjXZZHDTRy 47hZDM2uj38O+W4/5cXpw3q7Zv2s3EvHbuOotLXTAhtkpo+MwlDbu8Up8N+EkmxA xY/fNBXcpxt9zYtUh33a3s5WFZk7FdJeI6yj0X3W0nvdxONA1o5mDH4y9Mn1moOU j5dNzkUVEaVn1MOiO8aAr6wz+txEDpGfFnAw0xsIVn+W1XteGZyiTk8SOY/CYpBY h7bVjObr++nOoi97uqUgMlCU8a8lKkEv0FYEYxmV8nAidEgJUXKzEBk4H6hZ+zXA rtdqHsfri/yc7XYD+4HK1ApBQ6GivbBWkasJJZXntJlkzEsy1Go= =ANSo -----END PGP SIGNATURE-----