-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 16 Jan 2023 21:01:44 +0100 Source: libxpm Architecture: source Version: 1:3.5.12-1.1 Distribution: unstable Urgency: medium Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: libxpm (1:3.5.12-1.1) unstable; urgency=medium . * Non-maintainer upload. * Fix CVE-2022-46285: Infinite loop on unclosed comments * Fix CVE-2022-44617: Runaway loop with width of 0 and enormous height * configure: add --disable-open-zfile instead of requiring -DNO_ZPIPE * Fix CVE-2022-4883: compression commands depend on $PATH * Prevent a double free in the error code path * Use gzip -d instead of gunzip * debian/rules: configure: Set explicitly runtime paths for {,un}compress and gzip. Checksums-Sha1: 9a283cb1790919c629278f5bd4715d949d2e4428 2227 libxpm_3.5.12-1.1.dsc e133a7b837052ad6c6493e9693ebbc1f50bee15a 14815 libxpm_3.5.12-1.1.diff.gz Checksums-Sha256: 750fdc1979c8854cb5ee4a8836cf1cb6b3b6483680e8b386ba15f46ba93b5a97 2227 libxpm_3.5.12-1.1.dsc 3aeeb1d4a748597c6c904e47e15061951c5a649012528e259f3e3fe1907164d8 14815 libxpm_3.5.12-1.1.diff.gz Files: 42c7a2dba526b5a74b44fcd3d0aa8a15 2227 x11 optional libxpm_3.5.12-1.1.dsc 3da7e94dc78f7602e3641b2eddb93654 14815 x11 optional libxpm_3.5.12-1.1.diff.gz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmPG1zdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89ELTUQAIqCV6iHy3PuG7RZN+oaVT6yG5m/6w0X CfIZVNS36DvY8VFrOjqisvHGTVNMqZr5ehCEBKb9HZo7U5oBQfHvFWfImX1L6cLl ifdCl6rSPh7UcBZB6Na7i0iWaqYdqFXuAstE8W4yqidN3c4SJYWcTQozFS4+hjNu ishDPm/mpBZ71h+KfBnGRTFcOwx03EmQL22ApoandDEHUwe7imcFm4hTokG17Qeo 1Zb6TGc3C6YBrc/vMjcCfrLRia4hMiZNcseGnq77NbEvgV5l1kpehPJRe7fCwjlA g6UlrbEyMsROQRQz9dU5Ql/7M4xiN2WdZRe21vg5/Xb8QofTLslL8b8vDOPpjTNo RzPDJzdZRSm1wb+lpiU6S8PGHZhciYiI6+hvZtI7LgxjC/Iao6KxrZuX+UVOTRLi iDBEkJvhBgqCun7OeICeJRm2iMh9oRiykwOiWnQI4PmIORx1NMbCUz6qibFgHR1Q Xgx55unmNaqlikWu+j2B5NMJiWJ5Nve99FgAdBa0eFsg1NAu9b88am4lHSSZGiR4 sDGnT2U2kwSa415uuLjWjpE6sX3YSJgcJyf+zqHKj+Gr+AdiZuH4aMI2NZ+HZmxP fJjkzDU+o6CE3Dhlb2o9Xf7IHR0G0Q0X9nmUsDgufZiOKVIw+l5EzVDVIXf5XVlS iDNCNYkSP+Cn =VFtZ -----END PGP SIGNATURE-----