-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 10 Dec 2014 07:21:52 +0100 Source: graphviz Binary: graphviz libgv-guile libgv-lua libgv-perl libgv-php5 libgv-python libgv-ruby libgv-tcl libcgraph6 libcdt5 libpathplan4 libgvc6 libgvc6-plugins-gtk libgvpr2 libxdot4 libgraphviz-dev graphviz-doc graphviz-dev Architecture: source all amd64 Version: 2.38.0-7 Distribution: unstable Urgency: high Maintainer: Debian QA Group <packages@qa.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: graphviz - rich set of graph drawing tools graphviz-dev - transitional package for graphviz-dev rename graphviz-doc - additional documentation for graphviz libcdt5 - rich set of graph drawing tools - cdt library libcgraph6 - rich set of graph drawing tools - cgraph library libgraphviz-dev - graphviz libs and headers against which to build applications libgv-guile - Guile bindings for graphviz libgv-lua - Lua bindings for graphviz libgv-perl - Perl bindings for graphviz libgv-php5 - PHP5 bindings for graphviz libgv-python - Python bindings for graphviz libgv-ruby - Ruby bindings for graphviz libgv-tcl - Tcl bindings for graphviz libgvc6 - rich set of graph drawing tools - gvc library libgvc6-plugins-gtk - rich set of graph drawing tools - gtk plugins libgvpr2 - rich set of graph drawing tools - gvpr library libpathplan4 - rich set of graph drawing tools - pathplan library libxdot4 - rich set of graph drawing tools - xdot library Closes: 772648 Changes: graphviz (2.38.0-7) unstable; urgency=high . * QA upload. * Add CVE-2014-9157.patch. Fix format string vulnerability (CVE-2014-9157) in yyerror() routine which may allow attackers to cause a denial of service or possibly execute code. Thanks to Marc Deslauriers <marc.deslauriers@ubuntu.com> (Closes: #772648) Checksums-Sha1: 87634a814ed50be84162a6eac6680557c3b46eab 3266 graphviz_2.38.0-7.dsc 474bc72dbfe825de9686c88fcad9ab5083ad98e9 44120 graphviz_2.38.0-7.debian.tar.xz 3bf11ea7a149d25ca177b17b0506930c92fcc62a 3617592 graphviz-doc_2.38.0-7_all.deb c06b69d006c39aa4b2402c7c301ecc09449acee0 51272 graphviz-dev_2.38.0-7_all.deb Checksums-Sha256: 62883ac0dd3915c6cf67cda5cadd8c6423314c004bd791b781618d8743674bdc 3266 graphviz_2.38.0-7.dsc 312ab8215fbe1800664675cfc284aecfeff3ce699407523b5bdefee64cf1a53c 44120 graphviz_2.38.0-7.debian.tar.xz 5e25a05d8833795d1f1757b6c275c37e3c7fa70e8e3786dfac2862adb66156e6 3617592 graphviz-doc_2.38.0-7_all.deb 6a375986810b4086356a3f1a14096c8ec3452a5b9882bce04ef3339b01bf3af9 51272 graphviz-dev_2.38.0-7_all.deb Files: 4d093933d02b89ec55fba9775972e62c 3266 graphics optional graphviz_2.38.0-7.dsc 5cbcff92169d682471cdfdf58d215098 44120 graphics optional graphviz_2.38.0-7.debian.tar.xz b7f4f810365af31702d5582331fdfeb9 3617592 doc optional graphviz-doc_2.38.0-7_all.deb dfb8a0960673cb5703c64fa55c8c4fd3 51272 oldlibs extra graphviz-dev_2.38.0-7_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUiGjAAAoJEAVMuPMTQ89Egq4P/0ZINPYO96N/wMiYT80l9jb0 W49YgK+HnL6hHfeLZ39f67ch1uaeIPJqBkLIsHidsA9o9LKukdueT4U+75wuLEUX NJpRP6EBCtUtLcKH6so2L4CPvAH5tW3dzHnm5c/2m8h6f+JZTyjwTNS7dC2gmXH2 8XO/dPAd5O3go+tptl5t3insPi73VZup5HuqeoM15gOgkLo3qo4Mt3UH4g5R9zv5 DAGEjcv1dCa/jRcGHAr8OH+T06SEuSpHZuA+VxTvQ6P/IJnApPatmb4LIXJZ4tjs cj3q87Uqp5jA6ef04gDB2fOKQWpYKRVdgT9mIoTCbJow8F2Lobfq7q6BMQ42hoc3 idTKzeSMMmrV5TuIbPH23qHt2+pKd514x9bCMPmKgzSI7AITw1HyRn2yDup+mdmo brAGjMBc0nYdQymABPcjkzvoORGtXcApbNKfmPpFs+MOH1++BJ18En/DJi0XtsMl 1xPdOnELVq51JzzqqxpRQOepUqAN402hYhhf1j9bugBlSWusVdjuzf8fGm7/hGVt tKLYGwoUGGA5Mfd/RLrY6edS9NY6hMvXqlplCW83ztUs71jA9+5j6AlgnKvvQ4i3 U05ngRest4j6INDazGscmosMao6UWqxse50VdrVn0BNQljj/DzcAH5p6ftun9MSf jqN1tDKwRS8Z8iFCtc51 =lamf -----END PGP SIGNATURE-----