-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 12 Apr 2008 14:19:04 +0200 Source: cupsys Binary: libcupsys2 libcupsimage2 cupsys cupsys-client libcupsys2-dev libcupsimage2-dev cupsys-bsd cupsys-common cupsys-dbg Architecture: source all amd64 Version: 1.3.6-3+lenny1 Distribution: testing-security Urgency: high Maintainer: Debian CUPS Maintainers <pkg-cups-devel@lists.alioth.debian.org> Changed-By: Nico Golde <nion@debian.org> Description: cupsys - Common UNIX Printing System(tm) - server cupsys-bsd - Common UNIX Printing System(tm) - BSD commands cupsys-client - Common UNIX Printing System(tm) - client programs (SysV) cupsys-common - Common UNIX Printing System(tm) - common files cupsys-dbg - Common UNIX Printing System(tm) - debugging symbols libcupsimage2 - Common UNIX Printing System(tm) - image libs libcupsimage2-dev - Common UNIX Printing System(tm) - image development files libcupsys2 - Common UNIX Printing System(tm) - libs libcupsys2-dev - Common UNIX Printing System(tm) - development files Changes: cupsys (1.3.6-3+lenny1) testing-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix buffer overflow in gif_read_lzw function that can be triggered via a crafted GIF image file with a large code_size value (CVE-2008-1373). Files: 079f6d69938ccf062d81e23a02bd2118 1316 net optional cupsys_1.3.6-3+lenny1.dsc ccdd57ffd18d98c3249e87da3d931e94 4878467 net optional cupsys_1.3.6.orig.tar.gz b07094f5a74ac49e1bef292292986dd0 110398 net optional cupsys_1.3.6-3+lenny1.diff.gz faa5d3dbffb1b09fa7beb66410cb5609 1152820 net optional cupsys-common_1.3.6-3+lenny1_all.deb 6dda430ef1cc56a7baaab235734d91b1 159422 libs optional libcupsys2_1.3.6-3+lenny1_amd64.deb b1786c160bcbbef83d923ae1441d69a6 92244 libs optional libcupsimage2_1.3.6-3+lenny1_amd64.deb eedd2fe7f914a1eb08058f14e5a669f5 1942272 net optional cupsys_1.3.6-3+lenny1_amd64.deb 5bcf0f3e82cdd76901fb1a8092ef922f 88684 net optional cupsys-client_1.3.6-3+lenny1_amd64.deb f5a78536fa36001e8082a88cd85a5b83 390586 libdevel optional libcupsys2-dev_1.3.6-3+lenny1_amd64.deb 5edb9277e23bd853426a8646faad2989 60430 libdevel optional libcupsimage2-dev_1.3.6-3+lenny1_amd64.deb 92e349832e04dbf909b81f883b93e00c 38298 net extra cupsys-bsd_1.3.6-3+lenny1_amd64.deb 24637a183d7490f83c21b6cf7949f86d 1146372 libdevel extra cupsys-dbg_1.3.6-3+lenny1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFIAKurHYflSXNkfP8RAkR/AJ0d4zPYT1y1RWGEPSdx64BB2n4TyQCgtjhm YWR/X2nmjRSjuvfRSeQaez0= =A1hg -----END PGP SIGNATURE----- Accepted: cupsys-bsd_1.3.6-3+lenny1_amd64.deb to pool/main/c/cupsys/cupsys-bsd_1.3.6-3+lenny1_amd64.deb cupsys-client_1.3.6-3+lenny1_amd64.deb to pool/main/c/cupsys/cupsys-client_1.3.6-3+lenny1_amd64.deb cupsys-common_1.3.6-3+lenny1_all.deb to pool/main/c/cupsys/cupsys-common_1.3.6-3+lenny1_all.deb cupsys-dbg_1.3.6-3+lenny1_amd64.deb to pool/main/c/cupsys/cupsys-dbg_1.3.6-3+lenny1_amd64.deb cupsys_1.3.6-3+lenny1.diff.gz to pool/main/c/cupsys/cupsys_1.3.6-3+lenny1.diff.gz cupsys_1.3.6-3+lenny1.dsc to pool/main/c/cupsys/cupsys_1.3.6-3+lenny1.dsc cupsys_1.3.6-3+lenny1_amd64.deb to pool/main/c/cupsys/cupsys_1.3.6-3+lenny1_amd64.deb libcupsimage2-dev_1.3.6-3+lenny1_amd64.deb to pool/main/c/cupsys/libcupsimage2-dev_1.3.6-3+lenny1_amd64.deb libcupsimage2_1.3.6-3+lenny1_amd64.deb to pool/main/c/cupsys/libcupsimage2_1.3.6-3+lenny1_amd64.deb libcupsys2-dev_1.3.6-3+lenny1_amd64.deb to pool/main/c/cupsys/libcupsys2-dev_1.3.6-3+lenny1_amd64.deb libcupsys2_1.3.6-3+lenny1_amd64.deb to pool/main/c/cupsys/libcupsys2_1.3.6-3+lenny1_amd64.deb