-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 27 Jan 2024 10:32:25 +0100 Source: tiff Architecture: source Version: 4.5.1+git230720-4 Distribution: unstable Urgency: high Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org> Closes: 1061524 Changes: tiff (4.5.1+git230720-4) unstable; urgency=high . * Backport security fix for CVE-2023-52355, an out-of-memory flaw that could be triggered by passing a crafted tiff file with documentation update how to prevent it. * Backport security fix for CVE-2023-52356, a segment fault flaw that could be triggered by passing a crafted tiff file (closes: #1061524). Checksums-Sha1: 72516761177e955c8b5378b98f712239083503b3 2322 tiff_4.5.1+git230720-4.dsc b6dbbe04c4b1db88c5d4b140afaec39022c03e01 26260 tiff_4.5.1+git230720-4.debian.tar.xz Checksums-Sha256: 84f3fe1110e4633c897e63a6cc0122d2db3afb36140f089ec727ffe0f61facd1 2322 tiff_4.5.1+git230720-4.dsc a4ba563349fe2e53759703dce1aa476cbb3621ab3b4389df97faf60dd06067ad 26260 tiff_4.5.1+git230720-4.debian.tar.xz Files: 438d9ecffed1dc7fea0c5ce03ace6e61 2322 libs optional tiff_4.5.1+git230720-4.dsc 7010f692159675d50ed364f5a925c523 26260 libs optional tiff_4.5.1+git230720-4.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmW00lsACgkQ3OMQ54ZM yL+VhQ//eyxwyboe3I2oU0Oounre1YVYMMSUP3nb5quE09GmAu/vIrKmClqZonJI OqNLyWmNno6WY54XAaouEF3o8YWyTkdAlBPsbNuDEfopjM3S/58Fn2Tnx4d5tL4V QmsZaspeaVlraINeGk9l0zNtI2kMQ9z7R4rivdrAdwfNtYB9RJndmYWqbyXoE6T5 ojPeUHc+ksAMQNbfxP42vkJnn8K4taO5XZ1Hly/pNXEW1IxXOuf/1sSJ5Wpw6ZYo R4ya+3XAHxeh1BAgX/ho5nDLc47r1HbAAMHKwfTD+yTJhYipSsEhi4r1y8muRZba RXohAk3ykds8J9L6fYL47aYyFtG8QAcSCVL0pGuh9fhcmVfb5n4fq5EKiTo5aau/ 6rR9T+sx8bc5Qmdpft521AxAzR3+BD25O3TBQXAcQTXZyLWxQcib/mLBhOrK3HKO HxXHqcvbBLGBixXQ6hfFMXUXttXtK/4NQh6jCDPpQdE8Vd1u19ZUL5r7zuRCTUw3 OKncgnBbkXnYDdnIwRs4p1Ym1LQjSwitI8z2te+eMLSUG2XUP3+jJBPcTTAW4Lrf +OiZf/zgSspl8oK+Ov/tWh3lNmMX+4gFe2yMqv3UFqQD3GJUJFv8FxbxAV4qjQRJ G4Q8AbdulyZU82W8tlR7BF1tcJEhMhD87Uh1j9Art3bVOekpk9s= =CRZV -----END PGP SIGNATURE-----