-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 08 Aug 2016 00:07:27 +0200 Source: fontconfig Binary: fontconfig fontconfig-config fontconfig-udeb libfontconfig1-dev libfontconfig1 libfontconfig1-dbg Architecture: source all amd64 Version: 2.9.0-7.1+deb7u1 Distribution: wheezy-security Urgency: medium Maintainer: Keith Packard <keithp@debian.org> Changed-By: Emilio Pozuelo Monfort <pochu@debian.org> Description: fontconfig - generic font configuration library - support binaries fontconfig-config - generic font configuration library - configuration fontconfig-udeb - generic font configuration library - minimal runtime (udeb) libfontconfig1 - generic font configuration library - runtime libfontconfig1-dbg - generic font configuration library - debugging symbols libfontconfig1-dev - generic font configuration library - development Changes: fontconfig (2.9.0-7.1+deb7u1) wheezy-security; urgency=medium . * Non-maintainer upload. * debian/patches/0001-Properly-validate-offsets-in-cache-files.patch: + CVE-2016-5384: Fix possible double free due to insufficiently validated cache files. Checksums-Sha1: 200e56026be5dbd7b99ac25e67193b5ed6939d6e 2141 fontconfig_2.9.0-7.1+deb7u1.dsc 88a2d8be9578923a0227042af041130ab11ef3cd 1631768 fontconfig_2.9.0.orig.tar.gz 5a0e7225e9e1ba30dbd40ecc4d310b41472ee07e 54842 fontconfig_2.9.0-7.1+deb7u1.debian.tar.gz ecdd926153db95080fe96fdf85fbe5c489f334fd 232898 fontconfig-config_2.9.0-7.1+deb7u1_all.deb 1939bcfa40015b6f7c42a0b8cfdfadf263ab13e0 300316 libfontconfig1_2.9.0-7.1+deb7u1_amd64.deb 33edd40c8b6b1e1125e539bec65bf36cdb86abdb 348392 fontconfig_2.9.0-7.1+deb7u1_amd64.deb 2895560b0994c80d08b7db9732b9664ddc697c8c 100858 fontconfig-udeb_2.9.0-7.1+deb7u1_amd64.udeb fe557e9e06a7a0b9a180ab1c0dca0c52d98afcc1 859376 libfontconfig1-dev_2.9.0-7.1+deb7u1_amd64.deb 43017e5af917cc4628f9548b03b5f287353d6709 462160 libfontconfig1-dbg_2.9.0-7.1+deb7u1_amd64.deb Checksums-Sha256: 456cb212d45760f0be87a287a312291fdf687559f2fc5fd9a05fba0ad3e49e10 2141 fontconfig_2.9.0-7.1+deb7u1.dsc 43245d1fb1c1679038aec9271ced5d5f7613935ed21c7c39489f2fc7c7cce531 1631768 fontconfig_2.9.0.orig.tar.gz 24ad281e5003ca7575a561e209ecb27a703de956d10dcf00038b558569032c88 54842 fontconfig_2.9.0-7.1+deb7u1.debian.tar.gz d51cee6ee436b133a76596bcda4e296bc8aaec0cb92c4f34190c7452b5c3a7f2 232898 fontconfig-config_2.9.0-7.1+deb7u1_all.deb 1ae938f3647922e6195ecc741e61131a7994d81f71f0669480f35fb957550a32 300316 libfontconfig1_2.9.0-7.1+deb7u1_amd64.deb 7ff70c277a58cc7142dc2e034112d1edd5fda8ede2ca06935c2576e280ba53ff 348392 fontconfig_2.9.0-7.1+deb7u1_amd64.deb c399d9d409587e07812495e4258fdf6c117476dd290cf38fff91ceeb31d67072 100858 fontconfig-udeb_2.9.0-7.1+deb7u1_amd64.udeb 704c56bf6ec8b1ad122165482805e1b7a536bfcf9f08d98bf962e22af76cc772 859376 libfontconfig1-dev_2.9.0-7.1+deb7u1_amd64.deb 506d6b81fd88ca9bdc576af09bd40c2be0854831fb5a26bd6a0b897627f414db 462160 libfontconfig1-dbg_2.9.0-7.1+deb7u1_amd64.deb Files: 519b224e83e3b53b520e299f9de360a0 2141 fonts optional fontconfig_2.9.0-7.1+deb7u1.dsc 77f97eabc68368fa1c05f0399619b92a 1631768 fonts optional fontconfig_2.9.0.orig.tar.gz 1b054441df4535d506228d3744ead600 54842 fonts optional fontconfig_2.9.0-7.1+deb7u1.debian.tar.gz 0b87612bfe39ca0c65d850f4410a312f 232898 fonts optional fontconfig-config_2.9.0-7.1+deb7u1_all.deb 87ecf07c4590f514d420aa6ca8d4f46b 300316 libs optional libfontconfig1_2.9.0-7.1+deb7u1_amd64.deb 1650b0ae9eceb89b1046ca110923d24e 348392 fonts optional fontconfig_2.9.0-7.1+deb7u1_amd64.deb cc52825c854cfbc1ad6c2c8a00e9ee4d 100858 debian-installer extra fontconfig-udeb_2.9.0-7.1+deb7u1_amd64.udeb 25ced07080e237e64a7873313986bf51 859376 libdevel optional libfontconfig1-dev_2.9.0-7.1+deb7u1_amd64.deb 8211ca45fa565d4a96790016eebba291 462160 debug extra libfontconfig1-dbg_2.9.0-7.1+deb7u1_amd64.deb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJXp7m/AAoJEJ1GxIjkNoMC3lAP/iDRA4I/EJBV0oFAumfdBF71 j24tE4kslQ37NtvckuYrFA3zIhUhj17ktmapsYQ/UJnV0evfd90YrY72WoE5O5Hy dHavKHA4pNnZ3jHjodz9OzOI7uC63hRboPQPhSr/z/2aGKb2bhJ0HOtwuvVEWZra umznzYf4dTwdnmq4QxTEkwmQ2dlfTMc38BVVI9/8yCsIpNHuc3UeEtuqIiQ2ICXc E4m0GAvoxiakLSD5MqFPM1tWnakl3GquR9CaWk4hZSZntH24L14p861znmyf35dQ Bj/E5OBbPpcdKqtZAU4VGmQIllnqE8OYh9uQ82++zFhgdQa9cUzVbfDAHHr5nk5B JtipgnRdjPiUhKrHoAIxXL3QBWsi+TzeB8R/pm4gOcu4VLg4Ts9ENV0DJxHshv5T 2fpjyzMcwMixkB24pbpTLH4SFVEQtZ14mkW3qUDcgOLqsq2JQXYPwC0XnzStfggr b/yRTCl/9+ydV69ZtzPBcJxJG+hhDJidYrZoktfrawhGs6zvT1pDSTYRCeCG9r3X qzzERMOqVnulkaQIPAJsGAb7R31pd/nkVDJcf53to3sthecDM5XtjN83P6vF2Vlx QUbdn0D6Jd9YgIMZWrlxML7zLgyb8x+mZFTbaZf+GtNMRrT2VT1I/fPbPXIi+rFx 8OEFkwcBq2Vf5nlBFsu/ =JVeU -----END PGP SIGNATURE-----