-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 17 Nov 2016 11:45:45 +0200 Source: gst-plugins-bad0.10 Binary: gstreamer0.10-plugins-bad-doc gstreamer0.10-plugins-bad gstreamer0.10-plugins-bad-dbg libgstreamer-plugins-bad0.10-0 libgstreamer-plugins-bad0.10-dev Architecture: source all amd64 Version: 0.10.23-7.4+deb8u2 Distribution: jessie-security Urgency: medium Maintainer: Maintainers of GStreamer packages <pkg-gstreamer-maintainers@lists.alioth.debian.org> Changed-By: Sebastian Dröge <slomo@debian.org> Description: gstreamer0.10-plugins-bad - GStreamer plugins from the "bad" set gstreamer0.10-plugins-bad-dbg - GStreamer plugins from the "bad" set (debug symbols) gstreamer0.10-plugins-bad-doc - GStreamer documentation for plugins from the "bad" set libgstreamer-plugins-bad0.10-0 - GStreamer development files for libraries from the "bad" set libgstreamer-plugins-bad0.10-dev - GStreamer development files for libraries from the "bad" set Changes: gst-plugins-bad0.10 (0.10.23-7.4+deb8u2) jessie-security; urgency=medium . * debian/patches/0040-vmncdec-Sanity-check-width-height-before-using-it.patch: + Patch from upstream GIT to fix integer overflow causing memory corruption and a possible information leak. See https://scarybeastsecurity.blogspot.gr/2016/11/0day-poc-risky-design-decisions-in.html for more details. Checksums-Sha1: 2cadb77112deb92a07dbceacfbb78cac9ca5b34a 4155 gst-plugins-bad0.10_0.10.23-7.4+deb8u2.dsc 8d794838e009295061f30508c1fdaf83cea2f9b9 29828 gst-plugins-bad0.10_0.10.23-7.4+deb8u2.debian.tar.xz bac42155ed8ef5a335c4c463b2e76c247164e29e 843176 gstreamer0.10-plugins-bad-doc_0.10.23-7.4+deb8u2_all.deb 18acc04cb1a0e86e01a7f66aae634b34f7bdbc59 2001180 gstreamer0.10-plugins-bad_0.10.23-7.4+deb8u2_amd64.deb 4e7d63655ebd8087129a9f92c75d50d581babc27 5913802 gstreamer0.10-plugins-bad-dbg_0.10.23-7.4+deb8u2_amd64.deb f46d1d88c0303d87a8cc23ff514ab0daf89d2455 770400 libgstreamer-plugins-bad0.10-0_0.10.23-7.4+deb8u2_amd64.deb 97a9157f2ad3280b4eb0653750adb4900f5b451e 796468 libgstreamer-plugins-bad0.10-dev_0.10.23-7.4+deb8u2_amd64.deb Checksums-Sha256: cd9f065d6d585f3abc1eed06884fdc12deff7cdbe661b3883d0f9c767243f5ab 4155 gst-plugins-bad0.10_0.10.23-7.4+deb8u2.dsc ff2157905fec5005e0c8d788459157bf16dc557e6473c581b303ee468868a7c3 29828 gst-plugins-bad0.10_0.10.23-7.4+deb8u2.debian.tar.xz bad81e2e5dde0f5a479bf7675318ba74f58367bbf738502fb78faeb4202ab8ea 843176 gstreamer0.10-plugins-bad-doc_0.10.23-7.4+deb8u2_all.deb 650289a5f2aa90dc4c1c77a38258f40768c2e65ae39d53a9fb9d7e99b29ee093 2001180 gstreamer0.10-plugins-bad_0.10.23-7.4+deb8u2_amd64.deb 487a70f956717cdd2bffcc39d8370d93c326371e034d64a6993c0c33048fb9e1 5913802 gstreamer0.10-plugins-bad-dbg_0.10.23-7.4+deb8u2_amd64.deb 4a8dcb0ac45a36a6458ffd4ae5b7c5dcd7afdb43261947dfe63193e6bf03658c 770400 libgstreamer-plugins-bad0.10-0_0.10.23-7.4+deb8u2_amd64.deb f9fa959a57ecc5dfa0438054e1f06112f929be3ccecc6c976bd6d7caa2ac52d9 796468 libgstreamer-plugins-bad0.10-dev_0.10.23-7.4+deb8u2_amd64.deb Files: 34777a891a73a06db0a00ed6d3a20968 4155 libs extra gst-plugins-bad0.10_0.10.23-7.4+deb8u2.dsc fc3c788f44b71082ff04ecf2c3113191 29828 libs extra gst-plugins-bad0.10_0.10.23-7.4+deb8u2.debian.tar.xz fbb2878fc6610c8c5100da96de541d12 843176 doc extra gstreamer0.10-plugins-bad-doc_0.10.23-7.4+deb8u2_all.deb ccbe74217b03f685eb597139b0e7737d 2001180 libs extra gstreamer0.10-plugins-bad_0.10.23-7.4+deb8u2_amd64.deb 6e79052dab2895ea6c980e6b46deca95 5913802 debug extra gstreamer0.10-plugins-bad-dbg_0.10.23-7.4+deb8u2_amd64.deb 774809a626506e99360d868ddd77718a 770400 libs extra libgstreamer-plugins-bad0.10-0_0.10.23-7.4+deb8u2_amd64.deb 6ba91e3898701fc09dc20698330c2fec 796468 libdevel extra libgstreamer-plugins-bad0.10-dev_0.10.23-7.4+deb8u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEEf0vHzDygb5cza7/rBmjMFIbC17UFAlgtfpRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDdG NEJDN0NDM0NBMDZGOTczMzZCQkZFQjA2NjhDQzE0ODZDMkQ3QjUSHHNsb21vQGNv YXhpb24ubmV0AAoJEAZozBSGwte1klsQAM4QD7vlbqUqOPexV/74jg40/r7fUIyS 2l4I3AoWBqEIV0d5jF3Z+JYstiE2P2/AEj37CSRqiQCwFu7Ad+dO5gGO3PBt+FkX adywrMQkYPGTvEQrFRsJAyPJtw26jMjvV41zdDcnrR9wqP9M+ioJiY5SovOBvWaB gIzEdroXPutg4yY9A9gKa3IF2nlszqsXt9gNEt9ltM22G2k0hYwqyzh7GJL0MPnC i1Ryuk7j2/Ki5C0d0N5Bf9VQMqSaiDYXK2yzZTar1fAwjJv3hoEPdKzgJQ6BpY6A R+cgEVmwr8m/TjzPHQC+eljqMewnV5QmnvPP+fdQKN8+hdJ8ARvKLifw4hExfxa/ 8phkpHquWwCZMUOEy6BA9NqPW3YVWst5cetu+1tYvmdP3xbu2SF3H+aZAEEsnEbH JFYR/1Tmc8hDLaott73Okx9aI6oe60NQPtc188gXRWXFF0O1o3NSzzYGm1hC3e0u 0xf/MXaF2n/upJBgI9i7Emy3kq1u1coB+6wc1V9DehNI19D4wfey3J6bwB6BWKnN lZFe0n7CUN7tB18VCy4U4dkAXITjVX5zfJos7cg1YYffEaNgIiV1IBfgTr7RyzRh DJPjgwuXRB3dCvNXtdQHmZTuWIcxNneJIMBNlf8zhdu+I07xKQ+Lb1wC11wjUyAf 7GD0/Vrf5nig =H5a9 -----END PGP SIGNATURE-----