-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 25 Jul 2015 07:20:02 +0200 Source: expat Binary: lib64expat1-dev lib64expat1 libexpat1-dev libexpat1 libexpat1-udeb expat Architecture: source i386 Version: 2.0.1-7+squeeze2 Distribution: squeeze-lts Urgency: low Maintainer: Debian XML/SGML Group <debian-xml-sgml-pkgs@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: expat - XML parsing C library - example application lib64expat1 - XML parsing C library - runtime library (64bit) lib64expat1-dev - XML parsing C library - development kit (64bit) libexpat1 - XML parsing C library - runtime library libexpat1-dev - XML parsing C library - development kit libexpat1-udeb - XML parsing C library - runtime library (udeb) Changes: expat (2.0.1-7+squeeze2) squeeze-lts; urgency=low . * Non-maintainer upload by the Squeeze LTS Team. * debian/rules: deactivate unpatch, does not even work in +squeeze1 anymore * CVE-2015-1283 Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716. Checksums-Sha1: d3b64494e51452f51e1e4eb295dde99c4a5cbe59 2207 expat_2.0.1-7+squeeze2.dsc 663548c37b996082db1f2f2c32af060d7aa15c2d 446456 expat_2.0.1.orig.tar.gz 509f457425c5f23159c3f1ed1958839f0d3a0b09 147587 expat_2.0.1-7+squeeze2.diff.gz b973335bb5ccbd5108c18d0da3b31a6e958e50f3 165900 lib64expat1-dev_2.0.1-7+squeeze2_i386.deb 57ffd15b3442614b7bbc9800b069adb555e2924a 137898 lib64expat1_2.0.1-7+squeeze2_i386.deb 97fe7038b9303c5ccab515a48d3b3a0ecc700f19 213380 libexpat1-dev_2.0.1-7+squeeze2_i386.deb 28d296bc889bcb8f61877887aec7b3b4dc7dfd83 138966 libexpat1_2.0.1-7+squeeze2_i386.deb 816a7b2fa932f1ad536304e07ecf38208b963c14 64008 libexpat1-udeb_2.0.1-7+squeeze2_i386.udeb 9e2141e40bca1aef77de788b58bd8bc0ca6dd260 23838 expat_2.0.1-7+squeeze2_i386.deb Checksums-Sha256: 0e7b679dfbe19e7ce0d08803da55a4a20aaea7a8e458ed4793972ce5761274e0 2207 expat_2.0.1-7+squeeze2.dsc 847660b4df86e707c9150e33cd8c25bc5cd828f708c7418e765e3e983a2e5e93 446456 expat_2.0.1.orig.tar.gz 6fa750ff2648abb906689ceec9405fe02a168f505c5ce09522a2273606e4d5db 147587 expat_2.0.1-7+squeeze2.diff.gz a57efbe5f6b8911f4ff73d0cda4c1b392c0f291e9dac04bd3a3781726000635e 165900 lib64expat1-dev_2.0.1-7+squeeze2_i386.deb 6a644018248cdb1d014e8d225b69390cc37691d6e6b1c3b855ae0c1224cf4506 137898 lib64expat1_2.0.1-7+squeeze2_i386.deb 140010c22dba085530f705982ff38d0bdb9ced4e12aba0749010f7988bba99d9 213380 libexpat1-dev_2.0.1-7+squeeze2_i386.deb 2fe608989ff743d714fcc9d3a67397e05332bfec39775d85931666a1a1a6cd3a 138966 libexpat1_2.0.1-7+squeeze2_i386.deb 5a31221a58b95758a60dc53182b64a4c5189ddfbc73154b22f3fae7be3f0273d 64008 libexpat1-udeb_2.0.1-7+squeeze2_i386.udeb 7b7b64bdfc5ca3bccee71c2ef537ad76a61518eba4e59767fc260a4648c22202 23838 expat_2.0.1-7+squeeze2_i386.deb Files: 3a36b56aae64f79def9055c4e0fff38d 2207 text optional expat_2.0.1-7+squeeze2.dsc ee8b492592568805593f81f8cdf2a04c 446456 text optional expat_2.0.1.orig.tar.gz af9ec196f245f263697f74b854f9c86b 147587 text optional expat_2.0.1-7+squeeze2.diff.gz 3f3399be5e113cbf34fda9cef063ffa7 165900 libdevel optional lib64expat1-dev_2.0.1-7+squeeze2_i386.deb 79e4be33b23ee49b9ef61a121ecf553a 137898 libs optional lib64expat1_2.0.1-7+squeeze2_i386.deb 49c6fad0f408a57e904c07926423add9 213380 libdevel optional libexpat1-dev_2.0.1-7+squeeze2_i386.deb dda948caf9cb5878814c5114cafeb7de 138966 libs optional libexpat1_2.0.1-7+squeeze2_i386.deb 20db774c03449154264c36d96ed08065 64008 debian-installer extra libexpat1-udeb_2.0.1-7+squeeze2_i386.udeb 5c03fa37b240e189655a315d70d4c9ad 23838 text optional expat_2.0.1-7+squeeze2_i386.deb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJVs3g/XxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ2MjAxRkJGRkRCQkRFMDc4MjJFQUJCOTY5 NkZDQUMwRDM4N0I1ODQ3AAoJEJb8rA04e1hHxpMP/AkJqjzVzpFlJHlJYRYuZHS6 /2RZD46bz1QBhsZDLjymbkZ1heJLlkgWx6pJ0hlg74Ybr73QWZKB9hvGUHq/8OyK RrhXKL1TlPs59UulQZjETncRIM6OYmFy9KJvXoOIMKql0Xd90LSpLuyUpZXAcDlC GzLXeR5AEcqn16J2q6Y8R0wu9GCBOIXQzVwmVIfnvPEWNEVrtdiKmmnY9l5XkKs6 aie+bUFFfEdWOpVbtIwsKAWR72m9cw49ztxUqTzZpucYLQ0yP96hDfFZxorn8EHI g5N/x/T1F4laTE2lU2Rw0Q9fQXmvXtlaN4vEXJLfKwXlxkISQhexG4sKnmwlLr+a cpCd313vtUXjv4L4rKNftNaqR3KE+ZCI9yTK2ezrJoMqgvJBK6+CrjKj4zAIIuvJ sxik6sbRteqDg1W50bbiq2eBU4H15lc3foAWIlzhg+cMizarZvtwQgpdamezM8ua 9JnPg1N2wTYCX8P1YTLhwKg0m8pcf1Z6cjL0LgzLI+GSnFYY81Id6qKKl+dwi3I5 qIqAGkyi5cqFAa1CHnk6o9NL1eyGP4+cNIhQqhdz7HuwB5Caa/ZJ+nupHm/GStXg x9fWXWRWuRl7mTq7JdMocbxCGnm4jM9lxPW84ybluuLSdM/EJbxurVQqJQt6PgVb ntpuXlzSQMN7FS6jDG07 =ZDA1 -----END PGP SIGNATURE-----