-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 16 Mar 2018 18:12:39 +0100 Source: libvorbis Binary: libvorbis0a libvorbisenc2 libvorbisfile3 libvorbis-dev libvorbis-dbg Architecture: source Version: 1.3.5-4+deb9u2 Distribution: stretch-security Urgency: high Maintainer: Debian Xiph.org Maintainers <pkg-xiph-maint@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: libvorbis-dbg - debug files for Vorbis General Audio Compression Codec libvorbis-dev - development files for Vorbis General Audio Compression Codec libvorbis0a - decoder library for Vorbis General Audio Compression Codec libvorbisenc2 - encoder library for Vorbis General Audio Compression Codec libvorbisfile3 - high-level API for Vorbis General Audio Compression Codec Changes: libvorbis (1.3.5-4+deb9u2) stretch-security; urgency=high . * Non-maintainer upload by the Security Team. * Prevent out-of-bounds write in codebook decoding (CVE-2018-5146) Checksums-Sha1: 5c56cbc90b1be679fb013d0d9709f403a186c997 2566 libvorbis_1.3.5-4+deb9u2.dsc e8ed3eab78daaa97b5c88b3c45fedb5b64c6928c 11532 libvorbis_1.3.5-4+deb9u2.debian.tar.xz Checksums-Sha256: b8480875bda11dd6e676329568b64ff81722426d9178ad28f4f1f267dbd59d96 2566 libvorbis_1.3.5-4+deb9u2.dsc 95cabe08962ce58df7e55766be4115802097689700dc8bacfb9f22d495df6955 11532 libvorbis_1.3.5-4+deb9u2.debian.tar.xz Files: 996fbd9e9a684322cebcdd24e995a3ec 2566 libs optional libvorbis_1.3.5-4+deb9u2.dsc 6c739338d27b93a1117063250c62d692 11532 libs optional libvorbis_1.3.5-4+deb9u2.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlqr+5lfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89El2AP/0fbOA+KDZ7nEbrHAqb7YRpmQGDurAob Uel4MMizXHMN5dbZi8wWdDSKEPoKUPwRfbXyrXPPjZTwWQjEQd7Vq6XcxfaJmEY0 ORdhDTn1Em8SG/ZUHOYhc9A3n0xjvIGkm8W+CXfW+XG6JMb3t4frYR1MvizYInxn TxjCUlCkyROk9t5lAqgR5H8dhoSSM5cPhl/eGYNjkUM1MSc1jZwhSw0GamybubcW e5qbbp7VpFM47ko6Z3EGbZoHRsrI7LE88tpDh3Hr0CZap9cpDd3G3S19LeDTCmIE 7hj1rFN1VoZNIXgMl+buHwIjSe/KiaR0/+B9j6XE0VBaRbfvKHNuk2xQjSN3BDgZ Gw0PXGjiC7Q2yvwxYrqSOFJgwVRfatsCCJcq2KkqVWKXzkZfyZhmp4aN0fEO99ir opWph2WLjAJ3t6qvT5B1ntfJO8OO+/N1+UhuAk1JjPTZHtqIf74t6vcl+PKkmHEJ sP8xUOFAoDIPWi5lvpsJfqgEt3IRY5YITjNwHEMpro+T+WshbIeykS0dnbIlFSHO AdNQ33Fj4eFMkWA6/x6t8+dNVKT/xw9OHfux98wBbUn9V6LfYkRJQiUfWlFXoGJn dcyMgKS7DfrGtFjI4zi4yuulpbcWr3mw6pQFp/f1AL9Qo6csdOoDagwChsDNFjGg Aq5I/710onWB =ylIK -----END PGP SIGNATURE-----