-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Mon, 08 Dec 2008 06:35:53 +0100 Source: graphviz Binary: graphviz graphviz-doc graphviz-dev Architecture: source amd64 all Version: 2.8-3+etch1 Distribution: stable Urgency: low Maintainer: Cyril Brulebois <kibi@debian.org> Changed-By: Cyril Brulebois <kibi@debian.org> Description: graphviz - rich set of graph drawing tools graphviz-dev - graphviz Libs and Headers aginst which to build applications graphviz-doc - additional documentation for graphviz Changes: graphviz (2.8-3+etch1) stable; urgency=low . * Backport patch to fix a stack overflow in the graph parser, reported by IBM and fixed in 2.20.3. Thanks to upstream for both notices and minimal patches! Patched files are the following: - lib/graph/parser.c - lib/graph/parser.y This is CVE-2008-4555. * Update Maintainer field, package got adopted. Files: e64f158fdf6ce88fed201ab7ee924c04 835 graphics optional graphviz_2.8-3+etch1.dsc 7b8947fe82e7fc7aeea3a75cab6e5dde 43152 graphics optional graphviz_2.8-3+etch1.diff.gz cf14b254d740b9e3a957640d94d4ea09 1113870 doc optional graphviz-doc_2.8-3+etch1_all.deb cdeb83a3cdb81f494eb454a6195be043 1542474 graphics optional graphviz_2.8-3+etch1_amd64.deb aa03c3c45c45d852abb76c7a7a31b40d 138152 devel optional graphviz-dev_2.8-3+etch1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkk+c10ACgkQeGfVPHR5Nd3XugCgjWNQ9CZ9WiZhKFb51+IwrUwL glUAoLNmcpQKetG/wUHtFZsmH5nflRYK =hrsa -----END PGP SIGNATURE----- Accepted: graphviz-dev_2.8-3+etch1_amd64.deb to pool/main/g/graphviz/graphviz-dev_2.8-3+etch1_amd64.deb graphviz-doc_2.8-3+etch1_all.deb to pool/main/g/graphviz/graphviz-doc_2.8-3+etch1_all.deb graphviz_2.8-3+etch1.diff.gz to pool/main/g/graphviz/graphviz_2.8-3+etch1.diff.gz graphviz_2.8-3+etch1.dsc to pool/main/g/graphviz/graphviz_2.8-3+etch1.dsc graphviz_2.8-3+etch1_amd64.deb to pool/main/g/graphviz/graphviz_2.8-3+etch1_amd64.deb