-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 23 Apr 2016 17:21:25 +0100 Source: imlib2 Binary: libimlib2 libimlib2-dev Architecture: source amd64 Version: 1.4.6-2+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Alessandro Ghedini <ghedo@debian.org> Description: libimlib2 - image loading, rendering, saving library libimlib2-dev - image loading, rendering, saving library (development files) Closes: 639414 785369 819818 820206 821732 Changes: imlib2 (1.4.6-2+deb8u2) jessie-security; urgency=high . * Fix divide-by-zero on 2x1 ellipse as per CVE-2011-5326 (Closes: #639414) * Fix integer overflow as per CVE-2014-9771 (Closes: #820206) * Fix off-by-one OOB read as per CVE-2016-3993 (Closes: #819818) * Fix out-of-bounds read in the GIF loader as per CVE-2016-3994 (Closes: #785369) * Fix integer overflow as per CVE-2016-4024 (Closes: #821732) Checksums-Sha1: 7470354709a3d7be00b7167dfceb804ee46333ce 2024 imlib2_1.4.6-2+deb8u2.dsc a2482f66d66769fa36e6f3de7ec59c457ae67300 13808 imlib2_1.4.6-2+deb8u2.debian.tar.xz f99d69589a9dea8edabd3f1f3723d4738bbda80e 178094 libimlib2_1.4.6-2+deb8u2_amd64.deb 581a0354099e5031d0f605459bb5b41402770557 171020 libimlib2-dev_1.4.6-2+deb8u2_amd64.deb Checksums-Sha256: d912082e80c1e5e01e1a8133f798177fd6dcd97b29cfa66b1fc3a4b7707b367e 2024 imlib2_1.4.6-2+deb8u2.dsc 14cf3fc71964d3d2399abc8166b775e2d150d3c4102f736270a4c528a19480a3 13808 imlib2_1.4.6-2+deb8u2.debian.tar.xz 744136e9b44f76e61cf3aad4135da0368cb386fe4c022c720e82d414726b4f8a 178094 libimlib2_1.4.6-2+deb8u2_amd64.deb 0b852d7b22748a0b53d510272d1037f556b65a1f19fb5baeb7da376637c38b5e 171020 libimlib2-dev_1.4.6-2+deb8u2_amd64.deb Files: 5a98c6da18fe01d668d49074147df1f7 2024 libs optional imlib2_1.4.6-2+deb8u2.dsc 82a1d5e1d4827ab64b15ad1b38f20aab 13808 libs optional imlib2_1.4.6-2+deb8u2.debian.tar.xz d435a22396557ca7ae311f15103ea71d 178094 libs optional libimlib2_1.4.6-2+deb8u2_amd64.deb 4dcaa20ec5088cbbc8bd0c0045109b7f 171020 libdevel optional libimlib2-dev_1.4.6-2+deb8u2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJXG6gHAAoJEK+lG9bN5XPLInQP/212i3fZEXxFCaDt87RvJeZl 7Mg9yJqv0JVNcCr1CZR8UFYYIgDS8UHr8HjEX8JQibPn/YJkkUMzIcrCCWhC4h94 vHGLZYQJFz++zEDWaPi0dsQQEcMMO4wtRmO+SIcoBo53bxDcHpXQjdT5B5bM04/e V1gXYGzwJz5swGCd50Lw160+BPee7Qcjq4ngcam4nZA/v8Eb2Rz2DvenXUTLmybP zshAb93Oo1KyytC+16AuLInC91QYf/5E5rhEL6FYQIoy/yIaL35NdpxHGAI3wpb7 ZRY6WSRQCNlX/ROMlHG5X9JfErlQD4xHrvkzuZH48xGv2EjF4M0afrztZN8RtyWF 8v0y4tpGwUl+KYrIQlt5usPDYR8EXmywP4Zk9aMOd/hof8hSsQ4NSGUT3i5QIMOd VTRoOI1A1ApseBgwkqOmlQ2eyi7GXIOYmh9B09hrjnUmM86eXQhfMUjC4WK7k18I 6i5LU9kyvw48ORqD5DeQxHfkl/mBmwIsXHl9TbgoNLrtxvxhrUEuzlXqA/rORRnv bgq0iit9oOsozwEW0DsFzPksG+kauPVM405X9GPrdEAAN/jQwRNxkhjVUKz4vM7p x9tQSyOtWeI6sog8txP31RAo44rbV/fK6NZs//9yjw0yvlTtyFfn+xUu6OghRYjX uLVCkOLlujZXy1M3Y3Zh =HD8L -----END PGP SIGNATURE-----