-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 05 Oct 2023 14:24:36 +0200 Source: libxpm Architecture: source Version: 1:3.5.17-1 Distribution: unstable Urgency: high Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Julien Cristau <jcristau@debian.org> Changes: libxpm (1:3.5.17-1) unstable; urgency=high . [ Timo Aaltonen ] * New upstream release. - CVE-2023-43788: out of bounds read in XpmCreateXpmImageFromBuffer() - CVE-2023-43789: out of bounds read on XPM with corrupted colormap * control: Migrate to x11proto-dev. * Update signing-key. * patches: All patches upstream, drop them. . [ Debian Janitor ] * Remove constraints unnecessary since buster: + Build-Depends: Drop versioned constraint on libx11-dev, libxext-dev, libxt-dev and xutils-dev. . [ Julien Cristau ] * Update Vcs-* control fields. * Add ncompress build-dependency for the test suite. * Install man pages in libxpm-dev. Checksums-Sha1: 0b80ee16fa1ee7dbb0c5deac0cb1992d72684cd3 2271 libxpm_3.5.17-1.dsc 52aa8e25ffbb4ca96e199e45c11e6a7f1ac9d0e9 687199 libxpm_3.5.17.orig.tar.gz 31884a1b839898b093b1f0d88a40a52cf22f678b 833 libxpm_3.5.17.orig.tar.gz.asc 1034905d0e702ad69859f60b57e044bde9bd0a9b 49390 libxpm_3.5.17-1.diff.gz Checksums-Sha256: aae445c721ca497a374e356165dac20d1cd536cb91871f11cc4adb210a1e1f9c 2271 libxpm_3.5.17-1.dsc 959466c7dfcfcaa8a65055bfc311f74d4c43d9257900f85ab042604d286df0c6 687199 libxpm_3.5.17.orig.tar.gz 4a08ee4d18be1ffbbe69791a5c95471159b44a0cc7a5a30b0d46ae1eca1ebf2f 833 libxpm_3.5.17.orig.tar.gz.asc 3c8cb6d9c64d4e7cae4ed80a62f077f115ce96e57b40ec5fcdbb293cb3c3273f 49390 libxpm_3.5.17-1.diff.gz Files: 3b2294fba406aac12b67b3441f240c2d 2271 x11 optional libxpm_3.5.17-1.dsc 7ba169d45dc43bbad6aef9f644306427 687199 x11 optional libxpm_3.5.17.orig.tar.gz e8e76fc4ed3d5d8d13d9cb9c004d05a5 833 x11 optional libxpm_3.5.17.orig.tar.gz.asc 81418bf04561bfb33a980efc9dfd5c67 49390 x11 optional libxpm_3.5.17-1.diff.gz -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEEVXgdqzTmGgnvuIvhnbAjVVb4z60FAmUerIMUHGpjcmlzdGF1 QGRlYmlhbi5vcmcACgkQnbAjVVb4z62xVRAAtUjmOLs0KEKLUpK0UG17tAplsE4+ NUY9rtWh6+VQHsERoMP/p3N8xTrLi4FQd5CHhDj4bpoFf6x3b38RyibtnmvnecCP BFkAp3RFzCoYD1nhwDHIEenxEoSH+SFMYPx1NOjbIDbs/5q82HcKrCNzRELH4tRt rZwdnAic5Y5N3BkbsStzxzTUNL37St78c8SGFwXw3lyl+DR5GhehVwUA/omNdBJM 1aVdT3L/pDiVYxFI9bvPflrIJT+zKPhCy9livAor5dZ/FulLPs/IXt6etGMipyte M0e9z6lAyN/9/NplKR8onjNUsehGsEJAciXV/iV4NXSFN4v22LAuzDNCvwhdtqc4 sRV70BUGMb/+TJ6+o13Vi6qm5GbWlbQfgFUuU2jqwdUg4xtGLfJptpGUgFM7YoLV xFhB3GwRFXGtWYEhMGd5P9sFR6zAIxzLWcgWzceotr4+TGURvsaTqHRt65sLQ5+F WTRxv1kdvFIB9euFWNtj2znuBQnWJLq3eL+R7ysgQKQKdviBYLZkUh38IAVHxEvr RpNtPs9xu6oya7WzwOLKSDUVMCCN9Q08Nvg0ypqBKy7hbKlncFvxld/IbP1zR+3X tOuCsQ0WsJKujjTgBn8J4f/myAfn3XE16qKu4ojJMvxC4XZ9y9p7t04ElVFD+GwE 8QDOR6BSe5XJMI4= =rfWl -----END PGP SIGNATURE-----