-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 06 Feb 2009 22:11:20 +0100 Source: audacity Binary: audacity Architecture: source amd64 Version: 1.3.5-2+lenny1 Distribution: testing-security Urgency: high Maintainer: Debian Multimedia Team <debian-multimedia@lists.debian.org> Changed-By: Nico Golde <nion@debian.org> Description: audacity - A fast, cross-platform audio editor Closes: 514138 Changes: audacity (1.3.5-2+lenny1) testing-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix stack-based buffer overflow in String_parse::get_nonspace_quoted() used when importing MIDI files leading to arbitrary code execution (midi_parsing_overflow.patch; No CVE id yet; Closes: #514138). Checksums-Sha1: bc009737073117ee2585748d678ef409891f4074 1399 audacity_1.3.5-2+lenny1.dsc 35c1cf05fbc9408da1e751dff817870ded58be64 6445478 audacity_1.3.5.orig.tar.gz f6098d5d3170ba273b90a450cf9fa4cce389609e 23294 audacity_1.3.5-2+lenny1.diff.gz 1af540b379ed570c6179947a873a01619be65139 3328198 audacity_1.3.5-2+lenny1_amd64.deb Checksums-Sha256: 1a96b72a1a9e67750adb1ba236e270b56a1f9b50709ea4ed58bea4632b8f79af 1399 audacity_1.3.5-2+lenny1.dsc 6b79ad24c4e81b9e6c611c11ea0a520ef3fac446b32d40939064bda11e7452fa 6445478 audacity_1.3.5.orig.tar.gz af82ec36e359bb0aa24f75b1a48fd0098eddeb9cd8cfebda6ae8eaea760949ba 23294 audacity_1.3.5-2+lenny1.diff.gz e4e773ee0df9cbd4a3d7c386f2a0f1256cd8a943c42a5e313a6e8ecbefa3ebc2 3328198 audacity_1.3.5-2+lenny1_amd64.deb Files: 3219107631974f3f6bff459ca386055e 1399 sound optional audacity_1.3.5-2+lenny1.dsc 49fb288b0d8da28be53e06210fdc8521 6445478 sound optional audacity_1.3.5.orig.tar.gz 594d1d2822f0d1482211fd8da3a2f125 23294 sound optional audacity_1.3.5-2+lenny1.diff.gz a42a9a968aa925fad762bead64d79fd3 3328198 sound optional audacity_1.3.5-2+lenny1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkmMq5MACgkQHYflSXNkfP8llACcCLiEgP8tOMKWjCdY4zdeWSVL MhgAn2aqHR91pss/ZUwh/gEOjvt8Ahoi =nqMZ -----END PGP SIGNATURE----- Accepted: audacity_1.3.5-2+lenny1.diff.gz to pool/main/a/audacity/audacity_1.3.5-2+lenny1.diff.gz audacity_1.3.5-2+lenny1.dsc to pool/main/a/audacity/audacity_1.3.5-2+lenny1.dsc audacity_1.3.5-2+lenny1_amd64.deb to pool/main/a/audacity/audacity_1.3.5-2+lenny1_amd64.deb