-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 26 Aug 2018 14:35:05 +0200 Source: libextractor Binary: libextractor3 libextractor-dbg libextractor-dev extract Architecture: source amd64 Version: 1:1.3-2+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Bertrand Marc <beberking@gmail.com> Changed-By: Bertrand Marc <bmarc@debian.org> Description: extract - displays meta-data from files of arbitrary type libextractor-dbg - extracts meta-data from files of arbitrary type (debug) libextractor-dev - extracts meta-data from files of arbitrary type (development) libextractor3 - extracts meta-data from files of arbitrary type (library) Closes: 904903 904905 Changes: libextractor (1:1.3-2+deb8u2) jessie-security; urgency=high . * Fix CVE-2018-14346 (Closes: #904903), a stack-based buffer overflow in unzip.c. * Fix CVE-2018-14347 (Closes: #904905), infinite loop vulnerability in mpeg_extractor.c. Checksums-Sha1: 3aad973eb097cfe6668c95209473de11c1945e0c 2543 libextractor_1.3-2+deb8u2.dsc 613d0b80e83c79c3e05e073bcda0d0d0bd1f3336 7942021 libextractor_1.3.orig.tar.gz c545d23f39b9bb1ec02a557295f77de2d222ec34 16732 libextractor_1.3-2+deb8u2.debian.tar.xz 2ae62aacc34100232d8771f62b848ce84833ddde 112012 libextractor3_1.3-2+deb8u2_amd64.deb 84f327f71c0e3e6a25b20d258dca7ece18c4821a 450108 libextractor-dbg_1.3-2+deb8u2_amd64.deb 05429ae2fe6445077129fab80c04c809738758ff 25912 libextractor-dev_1.3-2+deb8u2_amd64.deb 3add2dac214e8f4fb99f1fb5603d7f3254bb472a 90454 extract_1.3-2+deb8u2_amd64.deb Checksums-Sha256: 5de54f86d5562527c6be4bbb8d4fdc43fb09ddec34d9328b8a80331b3e67c0b9 2543 libextractor_1.3-2+deb8u2.dsc 868ad64c9a056d6b923d451d746935bffb1ddf5d89c3eb4f67d786001a3f7b7f 7942021 libextractor_1.3.orig.tar.gz 9000343b9b0533480eec3df237e98ba68cc5753e7a6739ac2a00f2f933944a11 16732 libextractor_1.3-2+deb8u2.debian.tar.xz 3e24fe4058b3fcf1f475817e3ae40ee9c4525e63995859ddc1758b3a72c19e59 112012 libextractor3_1.3-2+deb8u2_amd64.deb 8c68fd6b84048b9f79acf985cdabdb869bd4616a23bdbd5e053ec98a926e2b82 450108 libextractor-dbg_1.3-2+deb8u2_amd64.deb ed2183a96a2e1ddf9f8431aada37eafec29a478beec7d5e9dde0973d11f6df60 25912 libextractor-dev_1.3-2+deb8u2_amd64.deb b087533e40a7728b7d769aac399807f09b9cddd04965f8d50d829eade7bca5d3 90454 extract_1.3-2+deb8u2_amd64.deb Files: 47b1e7d8cb85c3d69d4559d106d66f89 2543 libs optional libextractor_1.3-2+deb8u2.dsc 35b8913dbebafe583a2781bf71509c48 7942021 libs optional libextractor_1.3.orig.tar.gz bf6ee7cd1762da7afaf6a879e7164366 16732 libs optional libextractor_1.3-2+deb8u2.debian.tar.xz 71107655f51ca5b832bbd1ee7ad5467f 112012 libs optional libextractor3_1.3-2+deb8u2_amd64.deb 54411c07314be9f3a82e10eafcccb7fe 450108 debug extra libextractor-dbg_1.3-2+deb8u2_amd64.deb e142e472d60db07a6dfea045a75ddd57 25912 libdevel optional libextractor-dev_1.3-2+deb8u2_amd64.deb d9ba007d92fbb6448de2e100882634e4 90454 utils optional extract_1.3-2+deb8u2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAluCwG0ACgkQHpU+J9Qx HlhmfA/+JF5WNjU8EqpWH6I79oXqNd3oEGT62TmktfC3j8QD8O/1xZhtT1mpGfR9 Lsm+OdvSXpSau4djWy4wY8s5Nj8bH+18tCuc53USVt2aA4gIxwTRK12XXFSEwYjk 5rpBlZsoGf1Sdb/OvbubI+v4Xu+7yOcb+I86K+v43LPjgZODYIo2PfzI/2UAbjHY hsdZhCZezPn57Rt8jazRb74YeN8Eyq7Gi5nKsh5fp00H0SmNzsR0aeAYaqjBwveW LpWwLYgdNXar3ZGXQ1Z7GAyWZCqs3jWCGS5n3+3PBmYFpwVCfd5wuT5yhXtB1Y5P udcUrc0UdkLt+BcQDLYhWDIB5PuY8XSb6Si18aJD9UeYT9A+URwtnr84x507RiCB oLDy5P8Vi+n7WN7gQnyEjIqehH9165VixvmiG4Ju6rloN+vdx5bEwCBtF29A2t9W QMuiPpKYKkg3XngVsiWRT3XOkEsfSNBXszBTgqTkUGlv9KwBUKbdKF+96HK2CJ+7 rwA5aSGaAwcHkVL3G9uRDzoIKv3k067aTiVj+vJIurne1F2JsT+kDEx1iSxd4n3w ssAT0IgvatiFJk9EJDc6lpY8vBsfWt8Y1a4rTePji9BvHVecUpnWV7jj9K3L1PC2 AZ3GJ1h3SxxGbbJa4mUpFfv1N3EzKjJjC3hMga5kSTar0LtFHZE= =xgRY -----END PGP SIGNATURE-----