-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 01 Apr 2016 06:29:51 +0100 Source: lhasa Binary: lhasa liblhasa-dev liblhasa0 Architecture: source amd64 Version: 0.0.7-2+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Jon Dowland <jmtd@debian.org> Changed-By: Jonathan Dowland <jmtd@debian.org> Description: lhasa - lzh archive decompressor liblhasa-dev - lzh decompression library - development files liblhasa0 - lzh archive decompression library Changes: lhasa (0.0.7-2+deb7u1) wheezy-security; urgency=high . * Backport a patch from 0.3.1 to fix an integer underflow vulnerability in the code for doing LZH level 3 header decodes (TALOS-CAN-0095). Thanks go to Marcin Noga and Regina Wilson of Cisco TALOS for reporting this vulnerability. Checksums-Sha1: 2842932404f4125788553db8c32af4389b0f2450 1942 lhasa_0.0.7-2+deb7u1.dsc 7961e085d20d7813c8ecf9cfa543417a23de79e9 2244382 lhasa_0.0.7.orig.tar.gz 507e2d4c03fb33e3b5dbdf459c8924152b8ae0fd 2733 lhasa_0.0.7-2+deb7u1.diff.gz ef7ad1ee12e86ed672532d9dc4ea048e499bf9db 14040 lhasa_0.0.7-2+deb7u1_amd64.deb 25c22ba3e986482309621e524d617a0a37f65309 30814 liblhasa-dev_0.0.7-2+deb7u1_amd64.deb 0136c4afb3ff2e026b6b0d4b29dc98d0ad968ec7 23222 liblhasa0_0.0.7-2+deb7u1_amd64.deb Checksums-Sha256: b72a23f39303511e23ef912791beee7a9947fd26dc2ca0331482eca006768a77 1942 lhasa_0.0.7-2+deb7u1.dsc 6b2322d4a2ced96687b7b76a45fcfb575639c1ea29c87259fb3ff2aec88ad18b 2244382 lhasa_0.0.7.orig.tar.gz c46497a1a1635f0ed7c50e573f8a10bccdfa653bdedc29817e2b90de4ae03b84 2733 lhasa_0.0.7-2+deb7u1.diff.gz 7105022e3c5e2873dc58d3a9517c39a9f2aded91f6ce198e34df25bac985059b 14040 lhasa_0.0.7-2+deb7u1_amd64.deb 3770c178b9eb610b7df7926f1f1488c4c92bca58b9125588876ad10739ea7864 30814 liblhasa-dev_0.0.7-2+deb7u1_amd64.deb 98920ba920c22e9bc3705d42630db363a3249174ffd46658882a5e8d82cd0a42 23222 liblhasa0_0.0.7-2+deb7u1_amd64.deb Files: 34f78296fddb3262e5c92de345ff6dcc 1942 utils optional lhasa_0.0.7-2+deb7u1.dsc 3aacf03464688de942d8b954d985be11 2244382 utils optional lhasa_0.0.7.orig.tar.gz afa342a0a1828c1ae9ae8556ca9f431a 2733 utils optional lhasa_0.0.7-2+deb7u1.diff.gz d7c5e669dd2b8837e69432494a74a3b1 14040 utils optional lhasa_0.0.7-2+deb7u1_amd64.deb 8e61ccf9158713b6725ee3bd044a0e2a 30814 libdevel optional liblhasa-dev_0.0.7-2+deb7u1_amd64.deb e23645b49c8e2cdb7666ae5d05b06d5e 23222 libs optional liblhasa0_0.0.7-2+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJW/luHAAoJEAkHQJYGqqqqp/IP/3LDoGc0KzpWuObr0B3XWweq 69UYBKOGe0nJgqkaTbq0LUJlLh5pVJSqgLdCnvL46gWA9StQmjmgs3pHkRZoHRMF LnpD7XPKXB/c2zPuqcywIVfb+Ts3xMnnYw1rUyHmJQyNFSLlRQqq9TqCLZWls16g zVJaIRQxPX85xk/C4NgucQS5MBn0FV8HqzqkitpT/5wPgN7gn019UfaOScp3IlZ5 O091A7nAS3uH3tX0PpCXNFhgH4PAenih7dWuPT+sKOHv0/u0UTaSlOH72/ScFXCF A3DP4CPmeiKViWSqRUxXLFedUOnImaIYf/PshItjkCcLcwf/BIE/m10879+IdhfD KkVjbtcfOuF9/4X8iERlPbC+yS1js+gZx6C7IOL1IqvEEeLq2wd60Rfy6ClUI/Fk dVdPp05SJZ/w7ikWvGm8jOeoZC27KQkZJ9lquNMpct1psvQCKB5APHmPVVXjIXPb TfYYOvfd/spTo6uD2Wng0Xx6BodkNP1y2SsYeby6VbrPWGTGTuK3OTlGq+nlwqPq 7zBxuNU8bR4OyLO8K2RHySbuEoDjRnMnFhT6WD87c4us2dA04PhZLOJGl6wpTQ8r 8wPf2WKf31+h2whWtB4V9l4uoewMaSyewJvOttsPF64KkmdxmHhetFrp90n9zii0 YDQtdvR4/Ng8I4VUJe6w =RFWQ -----END PGP SIGNATURE-----