-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 06 Aug 2018 17:01:04 +0800 Source: libmspack Binary: libmspack0 libmspack-dev libmspack-dbg libmspack-doc Architecture: source amd64 all Version: 0.5-1+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Marc Dequènes (Duck) <Duck@DuckCorp.org> Changed-By: Chris Lamb <lamby@debian.org> Description: libmspack-dbg - library for Microsoft compression formats (debugging symbols) libmspack-dev - library for Microsoft compression formats (development files) libmspack-doc - library for Microsoft compression formats (documentation) libmspack0 - library for Microsoft compression formats (shared library) Closes: 904799 904800 904801 904802 Changes: libmspack (0.5-1+deb8u2) jessie-security; urgency=high . * Non-maintainer upload. * Add security related patches: - 0b0ef9344255 ("kwaj_read_headers(): fix handling of non-terminated strings") CVE-2018-14681 (Closes: 904799). - 4fd9ccaa54e1 ("Fix off-by-one error in chmd TOLOWER() fallback") CVE-2018-14682 (Closes: 904800). - 72e70a921f0f ("Fix off-by-one bounds check on CHM PMGI/PMGL chunk numbers and reject empty filenames.") CVE-2018-14679, CVE-2018-14680 (Closes: 904802, 904801). Checksums-Sha1: e3274dc93eae4a52536c9ff8a30a45aae21821a6 2106 libmspack_0.5-1+deb8u2.dsc 226f19b1fc58e820671a1749983b06896e108cc4 654193 libmspack_0.5.orig.tar.gz 760c5302fcc948b2e0278e8001487b8be615a3be 7120 libmspack_0.5-1+deb8u2.debian.tar.xz a3c175b079db2fd403c31b491e78ebc4cadd4c89 89130 libmspack-dbg_0.5-1+deb8u2_amd64.deb 06ccc3ceb5494adecfb7210d4510f0db2cba3ded 64384 libmspack-dev_0.5-1+deb8u2_amd64.deb 3fcca75004bfb9b9bd5ccd37dd7e1f2c89787e32 100882 libmspack-doc_0.5-1+deb8u2_all.deb a9fe444fc4028bb92feddb57db7830f5579c80c5 46094 libmspack0_0.5-1+deb8u2_amd64.deb beb056900a1f0009663062f48410569ffa1ef95b 6574 libmspack_0.5-1+deb8u2_amd64.buildinfo Checksums-Sha256: ed54f8e865445b848fbb1d8ef5caf51df89aaf3c5d2a7bdf382c7a8bc9a1f11b 2106 libmspack_0.5-1+deb8u2.dsc 8967f275525f5067b364cee43b73e44d0433668c39f9376dfff19f653d1c8110 654193 libmspack_0.5.orig.tar.gz f4976aa07ca1c3ba3195145e4927280395d2f2be03164b18240c301cf4543e28 7120 libmspack_0.5-1+deb8u2.debian.tar.xz 5bbac834e998924c7eecddc07ca4a2bc7c81f1f7d5952da2023d81d9294495ed 89130 libmspack-dbg_0.5-1+deb8u2_amd64.deb 072cd87de471283545b994289102d2a4c0e8eee38df307da24a01c31f6a3b280 64384 libmspack-dev_0.5-1+deb8u2_amd64.deb f4aac162111c0368e71e8e5b068156434155832ea534600daa3509e1552a290c 100882 libmspack-doc_0.5-1+deb8u2_all.deb 1ca8f6b75dd31ae0564c36a67e28d5c87558d0df6eb1280b3c4090f1c1ae3ae2 46094 libmspack0_0.5-1+deb8u2_amd64.deb 4fdf57c466b151486f0e9a76e78a4d932e30a9228f218fe4be97a502d15acef5 6574 libmspack_0.5-1+deb8u2_amd64.buildinfo Files: fd1b33fab74ad49ea79248c068038162 2106 libs optional libmspack_0.5-1+deb8u2.dsc 3aa3f6b9ef101463270c085478fda1da 654193 libs optional libmspack_0.5.orig.tar.gz b8f378421f2135a7de27323180116561 7120 libs optional libmspack_0.5-1+deb8u2.debian.tar.xz e36d9d70d44bd84b511d5bd13b9bc5ce 89130 debug extra libmspack-dbg_0.5-1+deb8u2_amd64.deb f1d87cf6106c9775a738913322738e0a 64384 libdevel optional libmspack-dev_0.5-1+deb8u2_amd64.deb 3e12874a5f3b1eb35ab785234be1b4a9 100882 doc optional libmspack-doc_0.5-1+deb8u2_all.deb 567e8095f9ca2896b17e018d4624d46d 46094 libs optional libmspack0_0.5-1+deb8u2_amd64.deb 1880b7c8af0222458de76d99b40d6891 6574 libs optional libmspack_0.5-1+deb8u2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAltoEogACgkQHpU+J9Qx HliA7xAAk9SaBZTGeF9FkSB83IZrkU879VaNeo/nnvDw09h9WauWZqlaCNBRCgmj dE6qkJOIjWOi4tn+C0pUO2yhVIoQ8tS6JCJs+iLFJn5V0Y1ni4mg20codxz0vP1o nPiKvz+5WZ12SQFyfWuUBs+57mXgRVGx8dMwuRimzCcXC7b+TjOWEB9c4nR8qDrv wYUDRcUzpmjqeRPiM7wKQL3o76STcOLsUIrBZRSSoBYrgro1WOLaS8Jo+oag3CHp 4kMvCPMOEMskB/7gGa6GKAu7UJpeNHPmd+QbIDG+wc7/462amqgLB/qpgfNAjfY+ MZOiIrPCk+oAzqgwhkTjiduwkxP35vDVXPrWCez6b/a+Ym8Jx/Q4AB3sDuv3MhvT OsCBEhS2fjRYeQmcdn5QGPM2gNat2r6mUkx3iKNCpiYTrkKVSwfXNsWpzIf4Qw7v 5q9RU9pRQOYLXPSUl1YzTjEO14TJLeAoylWRtwgcOX5vrcFA+xPSZW9+U0C9Hl3E 0h6yEgjZ6ulgVKGr2sLlDhPaVSIQl+m9o5kSbKA9yjUrVAefbFHK9JCWtXNiLxqF L01jXiajWmdzDZnXgGXe//Di/3lTIGENbTm0PS3MkcVmxci5zUVMBBNRluTUWeEI rseNwf9iLpj6zB33/VE+AIXTUwh4dg3V3y31Yj/BIV6FaQt8n4g= =jvAv -----END PGP SIGNATURE-----