-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 27 Sep 2005 21:13:42 -0400 Source: helix-player Binary: helix-player Architecture: source i386 Version: 1.0.4-1sarge1 Distribution: stable-security Urgency: critical Maintainer: Thomas Maurer <tma@hispeed.ch> Changed-By: Noah Meyerhans <noahm@debian.org> Description: helix-player - The Helix Community's open source media player Changes: helix-player (1.0.4-1sarge1) stable-security; urgency=critical . * Security update * Apply patch to fix CAN-2005-1766 (buffer overflow via a RealMedia file with a long RealText string) * Fix CAN-2005-2710 (remotely exploitable format string vulnerability via specially crafted media file) Files: 6ff062a280bab4db79c04e08278e28d6 908 graphics optional helix-player_1.0.4-1sarge1.dsc a277710be35426b317869503a4ad36d7 18044552 graphics optional helix-player_1.0.4.orig.tar.gz 1e3280253e2d60701b28b153863b2fd0 7788 graphics optional helix-player_1.0.4-1sarge1.diff.gz b3d2934818a2139f309f77e4acd50e3d 4289094 graphics optional helix-player_1.0.4-1sarge1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (GNU/Linux) iD8DBQFDOf6IYrVLjBFATsMRAoG/AJ9cAUJ2sdh2Eh8KZUKaa6Gsup6+EACbBI6X T3P8zR2RqsNNaom7CfsIVh4= =IV82 -----END PGP SIGNATURE----- Accepted: helix-player_1.0.4-1sarge1.diff.gz to pool/main/h/helix-player/helix-player_1.0.4-1sarge1.diff.gz helix-player_1.0.4-1sarge1.dsc to pool/main/h/helix-player/helix-player_1.0.4-1sarge1.dsc helix-player_1.0.4-1sarge1_i386.deb to pool/main/h/helix-player/helix-player_1.0.4-1sarge1_i386.deb -- To UNSUBSCRIBE, email to debian-changes-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org