-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 13 Jul 2023 19:57:57 +0000 Source: php-dompdf Architecture: source Version: 0.6.2+dfsg-3+deb10u1 Distribution: buster-security Urgency: medium Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org> Changed-By: Bastien Roucariès <rouca@debian.org> Changes: php-dompdf (0.6.2+dfsg-3+deb10u1) buster-security; urgency=medium . * Non-maintainer upload by the LTS Security Team. * Fix CVE-2021-3838: php-dompdf was vulnerable to Deserialization of Untrusted Data. * Fix CVE-2022-2400: php-dompdf was vulnerable to External Control of File Name thus loading unallowed file. Checksums-Sha1: dfeec5ca01c20d35ba4ec30754ec78f73a31c5e1 2189 php-dompdf_0.6.2+dfsg-3+deb10u1.dsc 33623ceed60e85b17e50527c9b61d0415314e53f 1118551 php-dompdf_0.6.2+dfsg.orig.tar.gz 602bea78d26ac65c71ef090e6e15b37824da3374 21008 php-dompdf_0.6.2+dfsg-3+deb10u1.debian.tar.xz bf673da92dbc496ddf7a5685d2a54768be8a0029 6435 php-dompdf_0.6.2+dfsg-3+deb10u1_amd64.buildinfo Checksums-Sha256: 69139bd31c0ef3d2731f11bf9035fad2c76e57e03c1f24494f58a803e2dcf9ba 2189 php-dompdf_0.6.2+dfsg-3+deb10u1.dsc e41a3ed39a5bff6177546b44de22330725f038eb72888792a78e2418cded8cb2 1118551 php-dompdf_0.6.2+dfsg.orig.tar.gz bc22f558d1c554cc60aa90fca16a8372f2248f814e7bbfe89e6dbcde8418b70c 21008 php-dompdf_0.6.2+dfsg-3+deb10u1.debian.tar.xz 0b147587be16da9f6f96148263c651aa253bda55f6850ebeaa3d97cbd29667be 6435 php-dompdf_0.6.2+dfsg-3+deb10u1_amd64.buildinfo Files: 53efb8385c3efb4dad315d54532a26e9 2189 php optional php-dompdf_0.6.2+dfsg-3+deb10u1.dsc dc5dc812c9c5ab16a6940a7401c4a941 1118551 php optional php-dompdf_0.6.2+dfsg.orig.tar.gz a865775b6173470c26d48bfcbf57c450 21008 php optional php-dompdf_0.6.2+dfsg-3+deb10u1.debian.tar.xz 03397b8995317527d60805db6c46e651 6435 php optional php-dompdf_0.6.2+dfsg-3+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmSwWFwRHHJvdWNhQGRl Ymlhbi5vcmcACgkQADoaLapBCF8UgQ//ZTHDJYZTdPrTEJdyv/KxakNPYdJIEgPC 0Bk2/KUoKohPcqUXLr/EgjVRrtnfrLeoU13ndTmLZMeGADygfJiXry0BeANrHdgh Ky1qAQeGkZZTiVyCIjbAOxlztwalh1oSkclY2Q4n7tenkmS5Jk4ER2kgwIiVzvwh deGJcw7SB+pem3emq0R/xWt6n/u89mf6MP7DWan/HhG+Jki+KqaseJ74m+wtcXeL LkKJFN1QA61+PI0XmLSbfIf3eWeHHe19kQEzpdnyfFNhLauaUhlAkOIxo45HArsY ZLmtL0wFaDYmUwQ7YBhguzZHe+/CTw8ZjGWVuxluX08OgPWNNry6bJXKGrCkgbuK PszUdr9rWwtEGwUNjOVzFgQLInR8VMJe0oj5LlQspZ/lzVpvOoASe7f+JgdXtSDY icK51TPln3nRrloNDSV2sjxuDo0NR1JIB3M9Bva+OqfkfdSMR2CUj00NGvnNlUW9 tqJkyPMNgg84NE8WHZu2FCyk8A1ze85DgFkkSOLCAyXyqtvSVy1/lUTt5XsSbWgc gLx6EsVsGeOl7kfazgYjdKMOoXWD1qG7X6TWPcduMGYOPAzRUbWZ3FJY16CJZN9h R2l+xPSdf3JC2yq45CxaMpdVFNrZDzCTNVbQ2l/Txu+JsMZGeQw28Q0OWFvL2nRD S0u+5Wsgm2g= =dwfl -----END PGP SIGNATURE-----