-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 20 Jan 2018 09:10:05 +0100 Source: gcab Binary: gcab libgcab-1.0-0 libgcab-dev libgcab-doc gir1.2-libgcab-1.0 Architecture: source Version: 0.7-2+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Stephen Kitt <skitt@debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: gcab - Microsoft Cabinet file manipulation tool gir1.2-libgcab-1.0 - Microsoft Cabinet file manipulation library - gir bindings libgcab-1.0-0 - Microsoft Cabinet file manipulation library libgcab-dev - Microsoft Cabinet file manipulation library - development files libgcab-doc - Microsoft Cabinet file manipulation library - documentation Closes: 887776 Changes: gcab (0.7-2+deb9u1) stretch-security; urgency=high . * Non-maintainer upload by the Security Team. * Do not crash when ncbytes is larger than the buffer size (CVE-2018-5345) (Closes: #887776) Checksums-Sha1: dd5beb91385674116346a3d5d4dd6f90235e76e6 2342 gcab_0.7-2+deb9u1.dsc 1fca43f2a8120060f5d12ac08c278b6e9f57986b 332248 gcab_0.7.orig.tar.xz 95056766d802bb6d4033b9065123daa5779db5a0 6848 gcab_0.7-2+deb9u1.debian.tar.xz 5975d2919a875a4540cba77d74ebff9536cf59ac 5967 gcab_0.7-2+deb9u1_source.buildinfo Checksums-Sha256: ab1fc4ea31192243244fa201293cfbfc89690a2d9b237c6daf76635f753bde9d 2342 gcab_0.7-2+deb9u1.dsc a16e5ef88f1c547c6c8c05962f684ec127e078d302549f3dfd2291e167d4adef 332248 gcab_0.7.orig.tar.xz 16580432f75ad5bba792adb6f7c02fd496a50efc7a95bb7efc691e56266c4a7a 6848 gcab_0.7-2+deb9u1.debian.tar.xz 9644c91d08fe1513aed607046db79e2308221dbee2c09211ba5026984063cc4b 5967 gcab_0.7-2+deb9u1_source.buildinfo Files: 265626a3387385af438c669e0fb74fa3 2342 utils optional gcab_0.7-2+deb9u1.dsc d8c54c340e56d0b6a8fe082fd04d8090 332248 utils optional gcab_0.7.orig.tar.xz 842cd44fd15eee45b3034435389babb1 6848 utils optional gcab_0.7-2+deb9u1.debian.tar.xz fb3733d883342ea934199e03f38227bc 5967 utils optional gcab_0.7-2+deb9u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlpi+mRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89Et48P/1FtkEwGLFd8xuPWpaXyBb3jTr5lWJWP 7EvKe+ulauIoUsjPeJLDcAPMsvtllSlOU+/E17Nu63vQrTIIeQ5bH7QB+bmWs6yp cljewkrehyG1aCzZ9yWY0zC1wrooCqQRYJSD+4dFtV032zIWo3AjWyDJuz738Jxx Wlk5hyrzFmETkJTfa5Otx1LTDuDNlkSzixfIz57ZWf1EXax9AsgUGoguKG7zrCLr oOdTEUG9QE3bkODZWEbjNdzjJjnxVGkNTXgm6FmeZyMqU/z8uRCo5E6QpUweJ9R0 KhsrSwOiea75V/FEcNJO2jC60o1WVmWdFgtG0ualxMG/GvDIVrxZG+smEYIA9KRh lne47+IXU7fzInZMfn6X6i90egY42hlwduSFkDrCrST6wi1FlqvZCba91t5oaodJ xrcouxXzD8wu6LAKTY9hSSOZrk6EGot/EbhEl6Y+FXVGIsX/FY8HFemdgWWdb16n /UD91x/j102zhPw32LriLK4yiuoype4x9k9xRTqzX9kelexieZVSkHQXOsHg+/m1 GsMTI+Gq7XYcPHvWqu9fivWDJHYTp80V+TAPWRgVhtd7pOqq8A3U3q9kaOR4flx6 pSQX7wozRtrzKnDPL2jX8k3Ape+iR1lKFxO0kz8oAFpdB8AE4/DgKw7bUHbGpMRf a3J7mTdEh6C3 =dhvU -----END PGP SIGNATURE-----