-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 01 Jun 2015 21:19:44 +0200 Source: libraw Binary: libraw-dev libraw-doc Architecture: source all Version: 0.9.1-1+deb6u1 Distribution: squeeze-lts Urgency: high Maintainer: Luca Falavigna <dktrkranz@debian.org> Changed-By: Matteo F. Vescovi <mfv@debian.org> Description: libraw-dev - raw image decoder library (development files) libraw-doc - raw image decoder library (documentation) Changes: libraw (0.9.1-1+deb6u1) squeeze-lts; urgency=high . * debian/patches/: patchset updated - 0001-Fix_CVE-2015-3885.patch added | Integer overflow in the ljpeg_start function | in dcraw 7.00 and earlier allows remote attackers | to cause a denial of service (crash) via a | crafted image, which triggers a buffer overflow, | related to the len variable. Checksums-Sha1: 9542ceb6ca50d9e9cacda631a329c80bde47e58e 1933 libraw_0.9.1-1+deb6u1.dsc bbc3eb7c4cf802f7b47f36afd9f5df3f0a22f234 3376 libraw_0.9.1-1+deb6u1.debian.tar.xz 3ca778d31d6ad8b9c2c933ef9f613a89f6b25890 101262 libraw-doc_0.9.1-1+deb6u1_all.deb Checksums-Sha256: ea435e45c8c6397b2f5d366e1496a2845c26d4643d63f173ae14808e26498600 1933 libraw_0.9.1-1+deb6u1.dsc 8bfa5d288b39413f635bc3cb3f491c01dd9f028c7424d9bdb54b236b4e2e2ce0 3376 libraw_0.9.1-1+deb6u1.debian.tar.xz 82209473c754fb1f0878c72dc024e5cf23ff6c7d034ed258d12f15b34f046ac9 101262 libraw-doc_0.9.1-1+deb6u1_all.deb Files: 8b10ad333eaed87bb7c193ef26b46d6a 1933 libs optional libraw_0.9.1-1+deb6u1.dsc b1604489d4e480631233ed583804f7b0 3376 libs optional libraw_0.9.1-1+deb6u1.debian.tar.xz fb8efc9711f14adfc93da8b4e8f884f0 101262 doc optional libraw-doc_0.9.1-1+deb6u1_all.deb -----BEGIN PGP SIGNATURE----- Comment: Debian powered! iQJ8BAEBCgBmBQJVdv3HXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRGM0REMDlGOERBODdEMURGNTA0NkM5OUIw NjEyRjQ5NDRFQ0RDRDVBAAoJEAYS9JROzc1atLEP/1G0PWBYK19a442qUVxdihOJ o2kZ06zkFtGydfo12PvxcsdYeP6M0ak2xuAkZEWN/c7nDu/8aUI6Y/zXWC3aKz8X VSL6Kz6Lu5gMc841wfQVWYNFP55xraARpUIdQ5x3f9Eid7us9eNtjEqemIR9VPjQ onB3VeWs97EVDDkh+rvqV7qapDh9wsDtcNwZroCopBaBAtlid9+7ZviVAQXDJHg3 +itlLf9jy57TB13CgUQdAT/mYKIzRTJTkiLEws4QD/q/rxKfK9d9W33KEt6RD+m+ zcpwzFRqz7u4DDi8eymniIX23SW9wLRAj0On3qyDtB73F16bkf2ZHBNf94ospMSr sQOgZFOKjzMh4SIjxUcBgdjLezJaZFycl9WA9bf1JZVxBeJ3jMXBf6aq9Z3IMIeX 579vc9Og2tEqVjEJ0fipPHRrQ2H1YKYxp8Y00evsA8FRb9yIeDrGkvkfwOe8P94N vVmM4CUl0ij6Ro89SvYppX07AGDontjWnPFpnMpY34f4c6HNBltdILMXcK3u9ZHk gUuo+GAPbsclixaAdM8o12pZOwgvF/Jg3OCobMgNjwLypD163XB8Qs/88NFn1Nu9 GJS7kHDCu0ZTe5KnNAmuvBOMUQxu2Xm0PpIeXiD3MkKNDvi8yUqJYFytkH7g4Zn0 p9ExRZBg/OyJ2bcmAkMg =HcGs -----END PGP SIGNATURE-----