-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 30 Apr 2025 20:53:34 +0200 Source: vips Architecture: source Version: 8.14.1-3+deb12u2 Distribution: bookworm-security Urgency: high Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Changes: vips (8.14.1-3+deb12u2) bookworm-security; urgency=high . * Non-maintainer upload. * Fix CVE-2025-29769: Potential heap-based buffer overflow when attempting to convert multiband TIFF input to HEIF output. * Add d/salsa-ci.yml for Salsa CI. Checksums-Sha1: f868a8dd63565772cf51666f6fda6fb6199c0989 2495 vips_8.14.1-3+deb12u2.dsc 9f2f925051c05e6c3302d9d1aaa4e72f799a3d39 21213381 vips_8.14.1.orig.tar.gz 5e7d797d9bc2ea24082bd1f00920b4e86d68d185 14916 vips_8.14.1-3+deb12u2.debian.tar.xz 2686360746067f25166b0dd51e12989fc5f1fc14 17808 vips_8.14.1-3+deb12u2_amd64.buildinfo Checksums-Sha256: 98226889993d86b8bb5074d1135fdda11fdcc96ab5b9345c064c190f215871f2 2495 vips_8.14.1-3+deb12u2.dsc a4a6b282216f7522b42ebb5cd64cfd82a0d1a632033e9c0502f021e945fed641 21213381 vips_8.14.1.orig.tar.gz 4f385972c51863a1003abb29d9d72faa0f2f968a799b20cdef567c524a9ac753 14916 vips_8.14.1-3+deb12u2.debian.tar.xz c00ec5743c765dd7aee3de4740ea900e228875cd6bdca76434e4a37cd8ddf859 17808 vips_8.14.1-3+deb12u2_amd64.buildinfo Files: 5493851cd682572351e15b712804992a 2495 libs optional vips_8.14.1-3+deb12u2.dsc 0f704121c0fff634569bf28bec28238c 21213381 libs optional vips_8.14.1.orig.tar.gz 1e638599a07fa7ef832bc0c4a937e5ff 14916 libs optional vips_8.14.1-3+deb12u2.debian.tar.xz f8a649063d83c6e6ba433a82a961854c 17808 libs optional vips_8.14.1-3+deb12u2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmgSdyIACgkQ05pJnDwh pVIPZA//RqE4oboQuR+FqBD1wK/z43InkvLW2LGJ0Ce+Hmt0Zq/Ueu+LBADJWNSg iCQCfq6XJEihQwhbl+sVyD61qEG5fsHTU838P2Su12gXMnZUyfQp0v1F/95VFJHc vtYP3Jp7p0pkn5wZhSbOLI2enhQeysMT531J1u5ScqP+TzbZpb2hm0kmizrgtzyC 2TfNEDdk5ONx8h7p7Mr3ZQSCFzs6swc+l1pN3Y19zsUq7Jm7eBC1upHMT4YGzD+e gZ9LzCabMf41IuOgvS2U0vVBUv05aPobl4UA+Hb/eoiFsuDE/D8MsbeXB5TZp5lN w9VmlO3f8MFGq+L4VXRM/TZc4WKA67D4Y9ntWIecmNOH2MQj/DfcV4e6cOp5mDYV 01WOOPUX+14KEiTE/iksUNNURdXg57BPXHpnyyRX46PamLaL5PHJ92cm3o1ErHwA zBOQO8+13pDqpjY+sgvd0nRw0p2oRiCgve/Zo5iaFZFazVzgAjnH3AW0WcYQbSMg 64hxhsa8ypW1kDwJPN30V9/b/Si9o/A7RUOSOvE9pROzqwAOx+gpVI3tmaZvSZYZ cj9Z+YLrZ7VsO4WansWPxLMJ6z08lSNRPJA6DsfkRwfzdTx7q1Ai9+YYOIouaIpc 5uzj5w1h/O6u0igyYQgUse9W4aJNALBjv7ArWerTgNt6lXc3/CA= =2tMU -----END PGP SIGNATURE-----