-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 17 Mar 2015 16:55:21 +0100 Source: libxfont Binary: libxfont1 libxfont1-udeb libxfont1-dbg libxfont-dev Architecture: source Version: 1:1.5.1-1 Distribution: unstable Urgency: high Maintainer: Debian X Strike Force <debian-x@lists.debian.org> Changed-By: Julien Cristau <jcristau@debian.org> Description: libxfont-dev - X11 font rasterisation library (development headers) libxfont1 - X11 font rasterisation library libxfont1-dbg - X11 font rasterisation library (debug package) libxfont1-udeb - X11 font rasterisation library (udeb) Changes: libxfont (1:1.5.1-1) unstable; urgency=high . * New upstream release + bdfReadProperties: property count needs range check [CVE-2015-1802] + bdfReadCharacters: bailout if a char's bitmap cannot be read [CVE-2015-1803] + bdfReadCharacters: ensure metrics fit into xCharInfo struct [CVE-2015-1804] Checksums-Sha1: 1d7d19b71678805e4b3a2b3139204b9967256a1b 2228 libxfont_1.5.1-1.dsc f85d51d7b26c66bf84b1c1394f282127d9bad12a 626873 libxfont_1.5.1.orig.tar.gz 4642cfc1878216fa4e51c80aac4f54290505c406 12991 libxfont_1.5.1-1.diff.gz Checksums-Sha256: 627dd07fa34d4760e935445bf6409d6eab82f83b04cb71a890a69ef37ab12d29 2228 libxfont_1.5.1-1.dsc 7c65c8ac581a162ff4c8cd86c1db9e9f425132eb65b1cba0c9e905c6cb8a45f5 626873 libxfont_1.5.1.orig.tar.gz b463e997327548774c1c9212a6c712e8d763106059d12cf55b9cda7facb234cf 12991 libxfont_1.5.1-1.diff.gz Files: 087d1f8325e74116a2747aeb0f7fc47d 2228 x11 optional libxfont_1.5.1-1.dsc 8b621c4a57c114eb07eb4977e3106f9f 626873 x11 optional libxfont_1.5.1.orig.tar.gz 8c9673f248d4c735c9372f732df38365 12991 x11 optional libxfont_1.5.1-1.diff.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJVCE94AAoJEDEBgAUJBeQMc5EP/RmohspCoAPwmX45L5QRFGSp LPV0xRD3qarCHq7W7i81ys3UmPDCFrMUfXGtQLT/v/pMLMTX7A7pltc72I/qF3dM ZKa8u5JpwrQOWpsRabtCmKKwrZBmKitTBRd5R1StO5O+US86YKgMfNB6H2bDXMcs wqWNBZX5TppXyVu9R9JRvNcm1DAjjwdMDSBnmXa3T18VBIUREcnMYB/HQUmBCmty AvYr206ybb4lA4PaY+kLc2ei368p1WD9UPu+uEqqGmXgYESKC4htY65gQ78jZMlr b+D9lvYbgFt8EdP40tybcmFjwdnPDbcQWfKwZhCtUGLEqvF9VpNJVWpUs7NauAC7 k3Aarfh3ko7KrlCkbgJ2iLUKpesnE6WQJvkkTClRXgyH5fZgmcBI6iYA9lzfZ/0v F8x2JCiDdPDCMPJ1ptRbgkouHN7gPI1uKBXsqP+QB3KuBuU+OOP9ZsibXl/aYjnQ mr+lPO6z3QoB+gMPEgZI3ghsU4SppWUTHlh7mZgLiOOn5fIuQvBQowSCNh6dqDXB gfFqU279M2oJD1jpeGiomW3PYqwJEE7q+XUr0FJ66v4OSL/Jbtp/tp9H3tEhJnqm pMkfNewn8IikY3C9nMn541GRRGoGMqwftbGuuQFe0JBBzjw66UY6i4rK8CJH9XVT TRrKes13T3gKotmLVXsz =GuiU -----END PGP SIGNATURE-----