-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 11 Jul 2023 19:13:09 +0200 Source: yajl Architecture: source Version: 2.1.0-3+deb10u2 Distribution: buster-security Urgency: medium Maintainer: John Stamp <jstamp@users.sourceforge.net> Changed-By: Tobias Frost <tobi@debian.org> Closes: 1040036 Changes: yajl (2.1.0-3+deb10u2) buster-security; urgency=medium . [Tobias Frost] * Non-maintainer upload by the LTS Security Team. * Cherry pick John's CVE fixes from 2.1.0-4 * Fix for CVE-2023-33460 was incomplete, also fix the second memory leak. . [John Stamp] * Patch CVE-2017-16516 and CVE-2022-24795 (Closes: #1040036) Checksums-Sha1: 81cfa50512d940752c0a4d2c93e20be1d351490f 1980 yajl_2.1.0-3+deb10u2.dsc 4617217f38b4b705b9e214c9095ad91c5698bc87 7256 yajl_2.1.0-3+deb10u2.debian.tar.xz 0dfa3c1b94dcf93edc8ad0fa590d63e4bf53a4ba 8175 yajl_2.1.0-3+deb10u2_amd64.buildinfo Checksums-Sha256: 3db9d159783812644e21a81b21244a4dca68a00b8a542376446c945cf65bbc2a 1980 yajl_2.1.0-3+deb10u2.dsc 3e563d22ba6c1a8f38e830dc2a84ee50bf30a29ef0c7f492cac219e6be3b3b6d 7256 yajl_2.1.0-3+deb10u2.debian.tar.xz fe85270071abf5547af42ecdbaff9620aeaa4d716e8175f154a3032af90c743d 8175 yajl_2.1.0-3+deb10u2_amd64.buildinfo Files: 051ea89f63c5c765bb29bc49efb6fb83 1980 libs optional yajl_2.1.0-3+deb10u2.dsc b21ac08714432a63b2aa8201a04d36f6 7256 libs optional yajl_2.1.0-3+deb10u2.debian.tar.xz 6c447581722a4df3cb8a577153e2a389 8175 libs optional yajl_2.1.0-3+deb10u2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE/d0M/zhkJ3YwohhskWT6HRe9XTYFAmStjjcACgkQkWT6HRe9 XTZFcA/9EMv0oW+5slYFm8reuFEeP+7KRWnwyM+b6tEEI7iJK0/XAZGCIUHFfnu/ tlRon6IsCF/0eJjVpIATjS0CRYWX5ll2u+uJTG88jYMTF83GGWbG9KRf+Y7UPScl iIr5E7D72U18I21DEEdUnDCeMVOml++b7wmwbtZIt4ZKyBesjSntDWphdmhil2Hq upcqH01SK+Cn17OTL8DnjTJ/Wrj3rk+eoHsPmlYtYijCroCzG+PayvE/S2YaI7KP UyCjM2uXz6wi7BlURhY/DeWrAisj7DQGXaJmO1ZG9eIbBqzRpuU+hThLZB4071PF OTKz2ir/M5XLAiJ2l8uY0/8EKlpZiFjZ+6DfciPvCT1AEydCZwLlgQhevqmkRgLU IXPwjWy+OWpZtDN0VC1e3le1iXfQOzHPl0oo9EiYd7zMgT2rlUBYd+s/9vy305sY AWRWr3HT0cy7l887pq1m3dfbXnj4wL6VXT1P5N+6UePuC96Fg0Ibp7gQ8J3U8ski RicjPpq6frAsH+7B2zethhStjiRFWYaH4oDuAw/8QsSUZe4dPTNqYSTFuZ1Vb+18 pRzanKlSSeK5/8554ouLEmGZJkeKdsvYV1aM9JWR3VRYtuAZBdlhyMYN2Rff5ni5 Y1wUaQDXbUvBJ96A8GpTT7E8rX9eL5/qEzDiMn8bdLBfvyaBuJ0= =Pudi -----END PGP SIGNATURE-----