-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 25 Feb 2022 22:03:02 +0100 Source: htmldoc Architecture: source Version: 1.9.3-1+deb10u3 Distribution: buster Urgency: high Maintainer: Debian QA Group <packages@qa.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Changes: htmldoc (1.9.3-1+deb10u3) buster; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2022-0534 A crafted GIF file could lead to a stack out-of-bounds read, which could result in a crash (segmentation fault). * CVE-2021-43579 Converting an HTML document, which links to a crafted BMP file, could lead to a stack-based buffer overflow, which could result in remote code execution. * CVE-2021-40985 A crafted BMP image could lead to a buffer overflow, which could cause a denial of service. Checksums-Sha1: 31ff02f579e244264ad5d0abc66d08e121103423 2298 htmldoc_1.9.3-1+deb10u3.dsc c5b03056bdce4238dfe27ab9e2f80ca9a335dc48 20968 htmldoc_1.9.3-1+deb10u3.debian.tar.xz f0a346ca5a6084afcc3e62030566bc47c68ab832 8412 htmldoc_1.9.3-1+deb10u3_amd64.buildinfo Checksums-Sha256: d979b0e6867f812bced2ae5349ff4807491f4457ab92f15944f1ad03547a4139 2298 htmldoc_1.9.3-1+deb10u3.dsc 08a4e337d8e214a39c24c18242b5d9e50de0842a5cbdf4003d4219a12283afa4 20968 htmldoc_1.9.3-1+deb10u3.debian.tar.xz 6bcd4b1c8c2009cf383e07e5356cc928b187eb12aaf0dafbab2d718e31da8590 8412 htmldoc_1.9.3-1+deb10u3_amd64.buildinfo Files: 25fbc1b69efc7240b4de9393f65ad426 2298 web optional htmldoc_1.9.3-1+deb10u3.dsc febf59bc385fa327060076c17d14a79e 20968 web optional htmldoc_1.9.3-1+deb10u3.debian.tar.xz 9fbe1ea703a0b8e47818560d26bdb861 8412 web optional htmldoc_1.9.3-1+deb10u3_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmI1DmRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR92gEACF1fYwsVHnEpAW/uK5h8HRIepNxRwY UppPgkOK6gYfTR2ZyfxFwgNYNtjrbAmME/gJZ1AhqkIZiFNLKLIOsJ05o0kMCEjg niPOTSJsgwR6AqygCwaahmm1mZAQfds+MeBujUsIDmU1Z1ixdQKoOwb9A/wnMYpz csNZ18wnJnx+jgkGZHOS0aIBayLsFOc6b/MIPppfxTCkMXLcnwsi/rXFh14WslYu Xs44u8TMG8Yb0jMw8GhcPwKHtmn67BU8VE+ODBjRNcNUKANdZ+nI0PwNOKspv05M 7G4PXDlAkpmnOQ87UIu+Msru2rE5jtsyDQpHhQu0WfURYuPA31Q0ncQ9gRvZB65R DHfVaYs2vOKDPrqIYz8Gg0YRHTmWXFUIc4W2iICLIXMr0uxD1YDPuXqkHIEutXiF eWPDez+weHOhuGa88jJ50Jp0JEMDvlQF/tqiPbBeyvOZG67wE+IdCEXiPbbOIDQk +1oHEGkjTk78JJVSHYVt/VlPLMXn5w0HkInBtu0JDjRwEBG48J8qlQ4qereDThwv 4Rjz1WHd6pCWnMvTOoh0wDf4sh3sb/zKP6hQqZzJPfTxvEe1s8jVDIlohhNGepVV 31Ty5+r62v/VonOaBmdJm44z5xsGofbXg5fripqejuhVUz5ouLsmQcRkof0ZdTOu eTouaKyAjN9ruQ== =+c0u -----END PGP SIGNATURE-----