-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 5 Sep 2023 23:16:04 CEST Source: aom Architecture: source Version: 1.0.0.errata1-3+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian Multimedia Maintainers <debian-multimedia@lists.debian.org> Changed-By: Markus Koschany <apo@debian.org> Checksums-Sha1: 46cf5643af0456a549a830fa63483d685c186edf 2407 aom_1.0.0.errata1-3+deb11u1.dsc a3e432cdd2f8b399be6b8c7399ce2d3242990340 1898808 aom_1.0.0.errata1.orig.tar.xz 45d057cfb77415789e0f8aacc7542571d929f8ae 24748 aom_1.0.0.errata1-3+deb11u1.debian.tar.xz 398c2aa90d29cfc40059d4125608621d4350a1a4 10384 aom_1.0.0.errata1-3+deb11u1_amd64.buildinfo Checksums-Sha256: 38ff7982c5d0e0a436f260e783c4c9324f89dc54f830436d8f0e79440e00b7de 2407 aom_1.0.0.errata1-3+deb11u1.dsc 1dd501c622d871acf31fb942bd3b73a00883fc10f7c498fec97b22c858ca415f 1898808 aom_1.0.0.errata1.orig.tar.xz 5f95bc34e84be5bd0610ac96ac72f1a2a42944e8b4d990b8c50edc22b4defcac 24748 aom_1.0.0.errata1-3+deb11u1.debian.tar.xz 2dc6cd00f01c909674674bb1ce60d3ae2612df00bad914cd7da92ab953d67861 10384 aom_1.0.0.errata1-3+deb11u1_amd64.buildinfo Changes: aom (1.0.0.errata1-3+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload. * Fix CVE-2020-36130, CVE-2020-36131, CVE-2020-36133, CVE-2020-36135, CVE-2021-30473, CVE-2021-30474 and CVE-2021-30475. Multiple security vulnerabilities have been discovered in aom, the AV1 Video Codec Library. Buffer overflows, use-after-free and NULL pointer dereferences may cause a denial of service or other unspecified impact if a malformed multimedia file is processed. Files: 6512ec338897f538f5253e485ffee510 2407 video optional aom_1.0.0.errata1-3+deb11u1.dsc a86870176602a9c12473b28784b8ad05 1898808 video optional aom_1.0.0.errata1.orig.tar.xz 9f080df18af41cef6fd1aaa92ea33759 24748 video optional aom_1.0.0.errata1-3+deb11u1.debian.tar.xz c739c08e8142be6ef440828dfe0bc508 10384 video optional aom_1.0.0.errata1-3+deb11u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmT3mtpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HktVEP/iWxosyJvmMxnBx+hgcMBrgEx15lMangNGPO a6RhyHNIONnxKmmtplhjfOhzlUYpPJokuzJxEFz1vqWJioPGKfXpf+faKMjnIDZZ MW+z2fFt8bAmbljudqMEfWY5dITrLCYwB23mVl2QB8NJfGlv+G9CexXFBaIWJiwg 7WUhovBBHAFUX3QosFK/NoXOjLXyX8oF1sA6/SWtCGeZHwtZRY68uVrVGuKFr4Kp aT0cJx0sL+ogSpnF1EdDD07wzzWSHindanDNSEsQwSyZbSO4T6QrR/jWdWVCTkcY LUOE4I8f0DoIuXGvO7nVykez22G+4qct3jUO53S44+7Gsk3OkUTp0cwUQe1iMoBP D48P/jee86ssig4mUTh/vkeOqEvsVWyDtzyRWbvFHQTAFJh0yd7mZ0m55Uw2TUci oQWdXYIflqvsMb6aiIXntHyEWVFUyOhi8G1agWF9iGQGP18JPN0a0nW6wI0cbRc2 gqu8/nkfKVTQO+sbKznf6zZyWhobKU58Qk9Bis3QVPeNmaKOvzwJ0OYZVmCWv0VP IVrMtM1mkT8T55+Wkoj8B6fTZRwwbTQViQdKRJP5CnZxBXFR1qwT/8Dr98BiJDyY qzZs0dV9qLc9m1d6IdIRcZO0fVDXn/Q8swQqjiCUAnZOgfVGaZs153BDSJFxm+C/ KE7cVVaR =L/1D -----END PGP SIGNATURE-----