-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 11 Mar 2018 10:28:36 -0700 Source: vips Binary: libvips15 libvips-dev libvips-tools python-vipscc libvips-doc Architecture: source all amd64 Version: 7.28.5-1+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Jay Berkenbilt <qjb@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: libvips-dev - image processing system good for very large images (dev) libvips-doc - image processing system good for very large images (doc) libvips-tools - image processing system good for very large images (tools) libvips15 - image processing system good for very large images python-vipscc - image processing system good for very large images (tools) Closes: 892589 Changes: vips (7.28.5-1+deb7u2) wheezy-security; urgency=high . * CVE-2018-7998: Prevent a NULL function pointer dereference vulnerability which would allow remote attackers to cause a denial of service via a specially-crafted image file. This occurred due to a race condition involving a failed delayed load and other worker threads. (Closes: #892589) Checksums-Sha1: 4236fb0ea9620d4a22a89c6c2c2e2d7fc7b4836e 2374 vips_7.28.5-1+deb7u2.dsc 57e7c9a38e86b786d719f21d3ca192c0e84dad10 3231903 vips_7.28.5.orig.tar.gz 24979d23760f1b6d638c9d752a25b717be446b7a 10388 vips_7.28.5-1+deb7u2.debian.tar.gz ad9e85fb47694a081471531dd61b2de25525dccc 449240 libvips-doc_7.28.5-1+deb7u2_all.deb e94e8547da4ea1fcf7c1995a4a404fd8ee6fc8f4 769310 libvips15_7.28.5-1+deb7u2_amd64.deb 5cc8cb72df0a735d5825cd594d18b134a30111e8 1016340 libvips-dev_7.28.5-1+deb7u2_amd64.deb 0ab335286046c5ffead29eb4fa5473cb18e31034 85950 libvips-tools_7.28.5-1+deb7u2_amd64.deb 81cc76aca0e5fb74ebb83aa53066847139c33425 4574112 python-vipscc_7.28.5-1+deb7u2_amd64.deb Checksums-Sha256: 88f6fad1f82d138aedc0f139f1695ae2d14e2b2dc81825db758dab4704a48562 2374 vips_7.28.5-1+deb7u2.dsc 5c5090f9d60819665384488df2378fa0594bfc290c1132605b2256bf58a6a983 3231903 vips_7.28.5.orig.tar.gz d36d95ffd040ed0e074efd5b2d03d38f5413a736bf23f040e5e62946de1de5d3 10388 vips_7.28.5-1+deb7u2.debian.tar.gz 3cf78b4ec6da9cf5ce7d8f03760e2484ba8495e48c7087dad9a09a213a5f85c2 449240 libvips-doc_7.28.5-1+deb7u2_all.deb e396ff1a0d643b73aac3c63fa1221a28afb2973f7a846e425dd244cf98632db3 769310 libvips15_7.28.5-1+deb7u2_amd64.deb bad3bf1625f280ccb969308928a39e4e043f06872d0be053b05b173224ac204a 1016340 libvips-dev_7.28.5-1+deb7u2_amd64.deb 0d66004e91cf490c19ed53712a639585b105173db02da323a228ea5fc6bf4543 85950 libvips-tools_7.28.5-1+deb7u2_amd64.deb 8f2868f918f8279d31be524664c5de5dc9e5c0e48c8a38597e2bc52bc63f9ffd 4574112 python-vipscc_7.28.5-1+deb7u2_amd64.deb Files: 0cc53e7b349d87a849cc6ca3e6dc079f 2374 libs optional vips_7.28.5-1+deb7u2.dsc 1d90ce705b4d7f81176e23dd790e280a 3231903 libs optional vips_7.28.5.orig.tar.gz 3e91cf35dadc275c024631758ce1375d 10388 libs optional vips_7.28.5-1+deb7u2.debian.tar.gz 38164a2eb3b72fec1b8dc4b04eb64ab6 449240 doc optional libvips-doc_7.28.5-1+deb7u2_all.deb 9a38549bce80d453c91ae1c0e90a08c0 769310 libs optional libvips15_7.28.5-1+deb7u2_amd64.deb f324257ebef6de8cc2cb890f0d1e5dfd 1016340 libdevel optional libvips-dev_7.28.5-1+deb7u2_amd64.deb 541c9e8efbe8b7d1efb9c231853b1192 85950 graphics optional libvips-tools_7.28.5-1+deb7u2_amd64.deb f56066c12b2e9eadfab6338caf32adcc 4574112 python optional python-vipscc_7.28.5-1+deb7u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlqla1UACgkQHpU+J9Qx HljNDw//e8BGguPkkLEKZIbGBQreUmDJMxfradrqtb2C+ldpFmkhe6pH94asIo0I doQMQzUixkpU3m7yGKtdvvudoj4s0w210SQWjhH1Bg5Yi3c6GdGNRtenDU7pqyrX gCmaDo3eUjKrvEWxIvOH4/knCA9XmGkfwA12mf7jalZ60egW1DlAplNrw99JYWcn +Vw4VPV/2cKv6O+h1cv3Nu19vCw/xEzV9sBjxyyZWwizkg0VcZwqX9cx9zKjcLS+ P0TNwETa4JCxXzxYLYGy8/+lp+G//Ft75Dn9KafvJh6svJb+76QEWHGfUajqFFSk 1Q6uoJQ4Qn1IM3IwvSs6RaExfvOs/7TwsPmB9owiNFVA7P4yTUMsCWcQHkRwu0sX zNlBrlL+HTo3pwJ3WSV6e2Y7YIEm27fkuy64vMHr55W0P4hp1ybid5J0ShLQuWVv oC00CGbbWzuXWItgFwj9z7HobPAfBLfO+fBqasJsjWFYhZNaKMrBEC86u6vZhqNs 6d3YP1XlrcqQTfFA1adLRJpd4IbQIW6I4wUHybHZ/NUpbjSc6cc6HQF8wciZtBn+ yRCUyIDdSezipBCzWKvCdAyYPik/K94BDyG6Lzn7H5kdF1Fh9CxVJMVNo4mBUhMM hdy7AwBho0zftLAjtnzseBEcncLYeocJPmFCEYzp48rcwS3RMjg= =2Kdw -----END PGP SIGNATURE-----