-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 19 Aug 2023 23:25:46 BST Source: librsvg Architecture: source Version: 2.50.3+dfsg-1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Simon McVittie <smcv@debian.org> Closes: 1041810 Changes: librsvg (2.50.3+dfsg-1+deb11u1) bullseye-security; urgency=high . * Team upload * d/gbp.conf: Branch for bullseye * d/p/996-Fix-arbitrary-file-read-when-href-has-special-charact.patch: Add patch from upstream 2.50.8 to fix a directory traversal vulnerability (Closes: #1041810, CVE-2023-38633) * d/p/Fix-compilation-on-rustc-1.40.0.patch: Add patch from upstream 2.50.9 to fix a build regression in the fix for #1041810 * d/p/tests-Fix-build-with-older-Autotools.patch: Fix another build regression in the fix for #1041810 Checksums-Sha256: e53781567bc5b1bbc83c4c212e88315a4eb659790431e24c979269acd7c0b0b2 3033 librsvg_2.50.3+dfsg-1+deb11u1.dsc 959b744c95516d8aa90034c3f48fb8c519440e8633649f71fdb0e39306824667 33936 librsvg_2.50.3+dfsg-1+deb11u1.debian.tar.xz b2fc5196e8d7ed4ae85bc7667133bf71129af291d5ae4af42746effa09731282 11627 librsvg_2.50.3+dfsg-1+deb11u1_source.buildinfo 6aa4e614292de77c6b5fa1fd05d6c5d658d4bb9857f678b7b57d0865d5e50116 16290880 librsvg_2.50.3+dfsg.orig.tar.xz Checksums-Sha1: 0080c49c026d4bdf7d7d987ed28d6a8d85971941 3033 librsvg_2.50.3+dfsg-1+deb11u1.dsc 6db6e6054454d500077d61d992d9b0edcd31c8c1 33936 librsvg_2.50.3+dfsg-1+deb11u1.debian.tar.xz b54edacb04b5ce83dd4d96090514648f935a6d20 11627 librsvg_2.50.3+dfsg-1+deb11u1_source.buildinfo a5daf615ef09be4aeedc312cbb0e44f8c680da37 16290880 librsvg_2.50.3+dfsg.orig.tar.xz Files: 111a82280e7c3f2be7046d516400eee1 3033 libs optional librsvg_2.50.3+dfsg-1+deb11u1.dsc 6c31383fbb38a409ec5bda4638006062 33936 libs optional librsvg_2.50.3+dfsg-1+deb11u1.debian.tar.xz c3ea8345c627b45e8a3ad1c016b533d8 11627 libs optional librsvg_2.50.3+dfsg-1+deb11u1_source.buildinfo 55172cde181acf4dcc0595cd296bc58f 16290880 libs optional librsvg_2.50.3+dfsg.orig.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEENuxaZEik9e95vv6Y4FrhR4+BTE8FAmThQaQACgkQ4FrhR4+B TE/HWw/9Fy3lmNCv+qZrQ9kOMSfJK0VJ/jzTf/WSJD+kDdHrp4HaTmQ9G3vJ+jLI mgE1jPPvDwgHrSWkjlb1HBWzRG9qu+LP/XL9bB7LpRRLdu/nsJVgQ/jn6PCgwcgJ djqLaGwrqzsyxkUHCZoCHj9ymYfktz2XIBLwWktpYMqfIhcFiHfNqxEX90p2LFzc S0Vu1WPncrlVv2iijyYilR0Kw/3ppyoS8LTPjRwRFdoVuVzEBExmA+75bGDZdWy3 W6ga2JTE1l44Vvqwiu9F8Gt+tVjSl5ffqiJh/rDq3Gxs8RSDNPnvWT4u+muc4+yB zrbHk+7/ZkwUarTzFxJ8O5z0s8i4PaBZgG6jT4VCygRsH0fpBwhx1BY5LJuDSBaD TsD6MYLQRsrfhYuQVA9nfklAVIvEUXJZXw09zcwFGF0k/gZfYrgQavcszej/Vn9E Fvou/sNdLkrq8mjrYknsfH3CaAMZ2R/r6NTWutY9NVLl/iXFph0zC8T1ZH60R2+E MSyrclOQ24kcQ3iZUtXhjMAfK/kcokUElgYQaXcySM4I7kNgpbXKdWWcxa7WIgNT JR15L7ZfGHubsFE3G8VQzG58ETfbgSM4N1zD3GXg8rpYPBL2prM0q/Txbp1Fzscy oRHNvaarfBglfrJt141hSaJuuPI415nVoevqbPkJpZGQ5Y30nl0= =tTOB -----END PGP SIGNATURE-----