-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 17 Nov 2016 11:41:08 +0200 Source: gst-plugins-bad1.0 Binary: gstreamer1.0-plugins-bad-doc gstreamer1.0-plugins-bad gstreamer1.0-plugins-bad-dbg libgstreamer-plugins-bad1.0-0 libgstreamer-plugins-bad1.0-dev Architecture: source all amd64 Version: 1.4.4-2.1+deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Maintainers of GStreamer packages <pkg-gstreamer-maintainers@lists.alioth.debian.org> Changed-By: Sebastian Dröge <slomo@debian.org> Description: gstreamer1.0-plugins-bad - GStreamer plugins from the "bad" set gstreamer1.0-plugins-bad-dbg - GStreamer plugins from the "bad" set (debug symbols) gstreamer1.0-plugins-bad-doc - GStreamer documentation for plugins from the "bad" set libgstreamer-plugins-bad1.0-0 - GStreamer development files for libraries from the "bad" set libgstreamer-plugins-bad1.0-dev - GStreamer development files for libraries from the "bad" set Changes: gst-plugins-bad1.0 (1.4.4-2.1+deb8u1) jessie-security; urgency=medium . * debian/patches/04-vmncdec-Sanity-check-width-height-before-using-it.patch: + Patch from upstream GIT to fix integer overflow causing memory corruption and a possible information leak. See https://scarybeastsecurity.blogspot.gr/2016/11/0day-poc-risky-design-decisions-in.html for more details. Checksums-Sha1: c9cfb5d0e9e7ce582069ad4b7b9a7ad21b661c57 4479 gst-plugins-bad1.0_1.4.4-2.1+deb8u1.dsc 7263f9877faffe6249bec7c68de4993f66678cfc 3821332 gst-plugins-bad1.0_1.4.4.orig.tar.xz f90a3c141023f03a7d03e2c51bc5de5bfa0aca8c 33328 gst-plugins-bad1.0_1.4.4-2.1+deb8u1.debian.tar.xz 2267402bca290d42d90a3414f6e077bedd137dac 1233842 gstreamer1.0-plugins-bad-doc_1.4.4-2.1+deb8u1_all.deb 2be212e46d78ae820e6002ace5d0705f5002c0e4 2367144 gstreamer1.0-plugins-bad_1.4.4-2.1+deb8u1_amd64.deb 4a45cce4a18b8aebf51d99b9a5f397b7adabec28 6696972 gstreamer1.0-plugins-bad-dbg_1.4.4-2.1+deb8u1_amd64.deb b64ecb35db914bf26b4a4be868c853ac4a13055f 1325952 libgstreamer-plugins-bad1.0-0_1.4.4-2.1+deb8u1_amd64.deb 089de5d6dead7981165237fa471f5879004c3a15 1109194 libgstreamer-plugins-bad1.0-dev_1.4.4-2.1+deb8u1_amd64.deb Checksums-Sha256: 6d296513d92d66613186dd9df0a4926a4c861fc860a0f18e3a06b27428e36fce 4479 gst-plugins-bad1.0_1.4.4-2.1+deb8u1.dsc e41b36105c0a13a2cb1ff9f559714e839b82dc3841484cd664790fb7947e55c7 3821332 gst-plugins-bad1.0_1.4.4.orig.tar.xz 370dafd34077217f478a4339bb9d71ed480a5f1ebe121365fdd1db94b11ea63d 33328 gst-plugins-bad1.0_1.4.4-2.1+deb8u1.debian.tar.xz 9d51401b172d9803276af5ca6a2f7e52e18c563127d234923c9542c51ed1e395 1233842 gstreamer1.0-plugins-bad-doc_1.4.4-2.1+deb8u1_all.deb 8ed77635d96028aa1e58c9d15696559d89713bff7101e208109fd88c39554f6f 2367144 gstreamer1.0-plugins-bad_1.4.4-2.1+deb8u1_amd64.deb ed5312c9cddb534a2d16cfc01ff8d70f11f17818aca607958471c631b3e68168 6696972 gstreamer1.0-plugins-bad-dbg_1.4.4-2.1+deb8u1_amd64.deb ceaeb625201e1bebb9e867100eeb97462236dbdf1255c4e9a4fcc37fce71a33f 1325952 libgstreamer-plugins-bad1.0-0_1.4.4-2.1+deb8u1_amd64.deb 5741b251e445f6691e0c076ec61587658115b912d05495c2707cc7403745eb6e 1109194 libgstreamer-plugins-bad1.0-dev_1.4.4-2.1+deb8u1_amd64.deb Files: b2ff41cd1bce7f5c89b8782d69f5f364 4479 libs extra gst-plugins-bad1.0_1.4.4-2.1+deb8u1.dsc 972c6e22dd2e44fcf0b04b9d810a56be 3821332 libs extra gst-plugins-bad1.0_1.4.4.orig.tar.xz 390b0a78880b3597cee40daddb75efa8 33328 libs extra gst-plugins-bad1.0_1.4.4-2.1+deb8u1.debian.tar.xz c36bf4aedfa128fa70d81fc5e60b9b56 1233842 doc extra gstreamer1.0-plugins-bad-doc_1.4.4-2.1+deb8u1_all.deb 039060f47549d65ecce6512ad6bd2563 2367144 libs extra gstreamer1.0-plugins-bad_1.4.4-2.1+deb8u1_amd64.deb 6b1c4b9d139ba2c4ed5466875edf5d61 6696972 debug extra gstreamer1.0-plugins-bad-dbg_1.4.4-2.1+deb8u1_amd64.deb 8f50f5f9fe4c4192331256672d8a5879 1325952 libs extra libgstreamer-plugins-bad1.0-0_1.4.4-2.1+deb8u1_amd64.deb d1d0799c073fe7a376a8ed6a9fc2b94b 1109194 libdevel extra libgstreamer-plugins-bad1.0-dev_1.4.4-2.1+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEEf0vHzDygb5cza7/rBmjMFIbC17UFAlgtfdVfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDdG NEJDN0NDM0NBMDZGOTczMzZCQkZFQjA2NjhDQzE0ODZDMkQ3QjUSHHNsb21vQGNv YXhpb24ubmV0AAoJEAZozBSGwte16kUQANBNx/JufL/REbmrnCPpY1lESPzQvF3i BTzTQ0LijslfV8bj8R98TIfu+dR0yKqMv1w2zBEfQIUZ1kW17EPYDo6i7diM9un9 Wd/Xo6rrDtJweOz7YVpTT3h2toBVs8aiSBTCrkzej1CJqw97tu7DLN9crarzOhg0 I5xl6VlXIFr3P3d9vErG5Y8qeDLOgySYbX2L7EmIoaDvDszMVI2iydGDcsTkQfZJ dL0pTxyVqurzhmMUY+NmzY96q/W4GziMWCPtTAqO0juMk96mUICCw23WseJ1TS0e fApr8u3HMstV7B492GEfo9hS7f0rSBy2LzBGLCkcYh33npdxQvskN/HHmEOfm8Ml D/I+HT5dgkWBfTquVmDdEDJnRQ4i9bS0kX8V8wd3EvdBu0+CVyL3rThoB/3ibfCQ iC5wb5ior2lop6jQ+lr3eKJGeZAN7O1CXT789HOpew8hGZSDNsopzkwoa6mbi/nE KaMvP505LJGtx1qV5HHOxudINv0NcOGcVIUVBfnROkrFTSKhixpuQw01outhdrQk yCpezDx4gzWI+/ehz3yliVjuxVdhmZ7K6bkt4crzgIQYO4m43Ikrrb/tSlXOQmqC vnu0EuKoiCy8CoYY6a7H/WHL+hmkVkaJ/0H0NhFq868BlXJZd9Y6DnI9QHjeHOwO Qo18XD0YwZoM =9J61 -----END PGP SIGNATURE-----