-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 29 Apr 2009 14:47:31 +0000 Source: freetype Binary: freetype2-demos libfreetype6-udeb libfreetype6 libfreetype6-dev Architecture: source amd64 Version: 2.2.1-5+etch4 Distribution: oldstable-security Urgency: low Maintainer: Steve Langasek <vorlon@debian.org> Changed-By: Nico Golde <nion@debian.org> Description: freetype2-demos - FreeType 2 demonstration programs libfreetype6 - FreeType 2 font engine, shared library files libfreetype6-dev - FreeType 2 font engine, development files libfreetype6-udeb - FreeType 2 font engine for the debian-installer (udeb) Closes: 524925 Changes: freetype (2.2.1-5+etch4) oldstable-security; urgency=low . * Non-maintainer upload by the security team. * This update fixes various integer overflows in cff/cffload.c, smooth/ftsmooth.c amd sfnt/ttcmap.c leading to arbitrary code execution or denial of service via a crafted font file (CVE-2009-0946; Closes: #524925). Files: 64611cbb471628359be5e3add390481b 806 libs optional freetype_2.2.1-5+etch4.dsc 355360a6157070ec1beed2a59b566053 35460 libs optional freetype_2.2.1-5+etch4.diff.gz abee35456605685cb9c439363f800173 355350 libs optional libfreetype6_2.2.1-5+etch4_amd64.deb 61b8048d1cbc5275322ed0d730bdbea7 671298 libdevel optional libfreetype6-dev_2.2.1-5+etch4_amd64.deb 35ca786b9430666664982428ea773053 149832 utils optional freetype2-demos_2.2.1-5+etch4_amd64.deb fc8b4e8e3ffe15eeeb7bcfb162e4a9e1 248282 debian-installer extra libfreetype6-udeb_2.2.1-5+etch4_amd64.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkn4uNAACgkQHYflSXNkfP/6kwCgisDenUyl6eoSID2lcfs4QUuQ 8B0AnRPjXh+fLSTqBFN608elWdj4EV9v =eRtF -----END PGP SIGNATURE----- Accepted: freetype2-demos_2.2.1-5+etch4_amd64.deb to pool/main/f/freetype/freetype2-demos_2.2.1-5+etch4_amd64.deb freetype_2.2.1-5+etch4.diff.gz to pool/main/f/freetype/freetype_2.2.1-5+etch4.diff.gz freetype_2.2.1-5+etch4.dsc to pool/main/f/freetype/freetype_2.2.1-5+etch4.dsc libfreetype6-dev_2.2.1-5+etch4_amd64.deb to pool/main/f/freetype/libfreetype6-dev_2.2.1-5+etch4_amd64.deb libfreetype6-udeb_2.2.1-5+etch4_amd64.udeb to pool/main/f/freetype/libfreetype6-udeb_2.2.1-5+etch4_amd64.udeb libfreetype6_2.2.1-5+etch4_amd64.deb to pool/main/f/freetype/libfreetype6_2.2.1-5+etch4_amd64.deb