-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 26 May 2015 18:09:20 +0200 Source: libraw Binary: libraw10 libraw-bin libraw-dev libraw-doc Architecture: all source Version: 0.16.0-9+deb8u1 Distribution: stable Urgency: high Maintainer: Debian Shotwell Maintainers <pkg-shotwell-maint@lists.alioth.debian.org> Changed-By: Matteo F. Vescovi <mfvescovi@gmail.com> Description: libraw-bin - raw image decoder library (tools) libraw-dev - raw image decoder library (development files) libraw-doc - raw image decoder library (documentation) libraw10 - raw image decoder library Changes: libraw (0.16.0-9+deb8u1) stable; urgency=high . * debian/patches/: patchset updated - 0001-Fix_CVE-2015-3885.patch added | Integer overflow in the ljpeg_start function | in dcraw 7.00 and earlier allows remote attackers | to cause a denial of service (crash) via a | crafted image, which triggers a buffer overflow, | related to the len variable. Checksums-Sha1: 8c26db20f99b10001b74e889107cb542a6200e37 2336 libraw_0.16.0-9+deb8u1.dsc 492239aa209b1ddd1f030da4fc2978498c32a29b 1472935 libraw_0.16.0.orig.tar.gz 8b2dbe50ba7db5bd177c80aaba0f6fcbcddfa003 26852 libraw_0.16.0-9+deb8u1.debian.tar.xz 006f468c6043b86ec54eee5f8232db6fff6f12f4 109338 libraw-doc_0.16.0-9+deb8u1_all.deb Checksums-Sha256: 0b352607c1adaa81f6debb1d4491a9668aebb6a3a40781d0712738317e9a8d60 2336 libraw_0.16.0-9+deb8u1.dsc 71f43871ec2535345c5c9b748f07813e49915170f9510b721a2be6478426cf96 1472935 libraw_0.16.0.orig.tar.gz 9d8fc86489afd57f0be225e37c210b90e4fede7b6f348c0b10e814f79a990893 26852 libraw_0.16.0-9+deb8u1.debian.tar.xz bb2390c3f26013ad60651ef705aefed4cc75842e8015e4160465ff13970ab336 109338 libraw-doc_0.16.0-9+deb8u1_all.deb Files: a2a1fb0b8575067816358dc68536597d 2336 libs optional libraw_0.16.0-9+deb8u1.dsc 21f569be043057b754d87e3062e2345a 1472935 libs optional libraw_0.16.0.orig.tar.gz 7156478db652c0ecfabbe02db2620d7c 26852 libs optional libraw_0.16.0-9+deb8u1.debian.tar.xz ff5b1b891136ed397f29b1dda4778741 109338 doc optional libraw-doc_0.16.0-9+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- Comment: Debian powered! iQJ8BAEBCgBmBQJVaAkFXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRGM0REMDlGOERBODdEMURGNTA0NkM5OUIw NjEyRjQ5NDRFQ0RDRDVBAAoJEAYS9JROzc1aWjgQAI1Nf85URua6syG56T9a4kk4 xH8VEgYQrTWyIePZ8GoxgJmPe2R+zdnptZG7f0nVsSX6XgGw2/fKshpeMbhWR3XF waeFpQjeerHCY85TddI6Dooxctlk80YlJF0GNq81hLgyN0hTh0nIL/wQJqIuEBb2 Y5nXMOQm16kGqZqZjGBcTHV4q0PoHDnX/4H/YHw8kIug3d+b6K7rPS/dBzD2pm9A pXFdHQ6MOOk4WluqziuzAMIVF7A+ZLBbzBtVWfHMxXVHMjQ/+N0Dk3q3UxOGGEor HWeKjcK5vxbZWF+mX3tNuLoJESzKLZeWk0nrIKz4T2a+LCLDdzUMWPt5eMmDp7JG XUhvjD3t3LZqKzcIRQ2NxisnaMyh6RgWQ9eMYvGmv1efh8w8SfXgB8r3PWC0ex0e a2lf22+o/gaKe5GkniE6JyazsRRFNi1IpThMrU06zSwItmqfR2Bepm/M1/UTwUdP 02cExvPsUjeRH+DeoB9QD7mlaYEQqHzqCqfhF848SRrA6AnWCi2mXMNRwIJWn4fh fT3bZ//dUbSSk6UavyVCa2qf93rhzIirFoUqGfR9laeNChoWkoprlXbqg9o/+cE0 Ej2isGanAJUqo4hE4YVmx9L/kt4a+vwgNvpz2CWmXjgxRKw5lY1nhPth0aL4AcP8 0WI3RSbU8EHdfiHlNNWm =DTqA -----END PGP SIGNATURE-----