-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 08 Sep 2018 20:31:54 +0200 Source: discount Binary: discount libmarkdown2 libmarkdown2-dev libmarkdown2-dbg Architecture: source amd64 Version: 2.1.7-1+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Alessandro Ghedini <ghedo@debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: discount - implementation of the Markdown markup language in C libmarkdown2 - implementation of the Markdown markup language in C (library) libmarkdown2-dbg - implementation of Markdown markup language in C (debug) libmarkdown2-dev - implementation of the Markdown markup language in C (dev files) Changes: discount (2.1.7-1+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2018-11468, CVE-2018-11503, CVE-2018-11504 and CVE-2018-12495. Several heap-based buffer over-reads were found in discount that allowed remote attackers to cause a denial-of-service via specially crafted files. Checksums-Sha1: b378829d2c344752ee599685587a80b71fe2381e 2223 discount_2.1.7-1+deb8u1.dsc d1711e924472e24433b99bd4990d6c587e1286a0 105935 discount_2.1.7.orig.tar.gz d325e25224105e3baf2f8a94008a003127d92efc 5160 discount_2.1.7-1+deb8u1.debian.tar.xz 569e9dcf060f2988afe678280211ddcfe88c1ec6 20512 discount_2.1.7-1+deb8u1_amd64.deb f41d656dc8d9672464e5254c88990a59de959c0f 34312 libmarkdown2_2.1.7-1+deb8u1_amd64.deb 93230c5886e3ec85be9ab8f3eb6f2e5f0edd5b6f 21710 libmarkdown2-dev_2.1.7-1+deb8u1_amd64.deb c985a253926ade9813fff750b86689132b0ed886 67360 libmarkdown2-dbg_2.1.7-1+deb8u1_amd64.deb Checksums-Sha256: 3c9194a8827df6b9ce905d7a6af2ef30d9f3a7f61e9e35f3bb0b2d5d7d0c089f 2223 discount_2.1.7-1+deb8u1.dsc 30dfc4a0fafccfba9234575cd8c659823b124295caddccf79d814c0f2d330d5f 105935 discount_2.1.7.orig.tar.gz d705dee50c5ad4337214d8e0fbf7db7f71a1da8774ef02073a365f7f9c25f056 5160 discount_2.1.7-1+deb8u1.debian.tar.xz da6144e2e969cb2d4e4eccf72433b2bd9879ea29b8f0f85c299943c7f8b72738 20512 discount_2.1.7-1+deb8u1_amd64.deb ddaa1b56e214d291c842d19c339a34e6d0d56d349d6d1cbd8c8bf02c4d9966a4 34312 libmarkdown2_2.1.7-1+deb8u1_amd64.deb 865120cbeff24d8a10db89ce8fc2d110d840e7aceff957916cbce14c188c59f8 21710 libmarkdown2-dev_2.1.7-1+deb8u1_amd64.deb 166c213d40cf794d4e552d0a816dfaf63152f8058329357091946aeda0dc70ee 67360 libmarkdown2-dbg_2.1.7-1+deb8u1_amd64.deb Files: 282f678a4fe38d6f06a89fa906b40884 2223 text optional discount_2.1.7-1+deb8u1.dsc bc60abde3d36fe891802c59544591d63 105935 text optional discount_2.1.7.orig.tar.gz 3fe0998dbc3862668d503ad7997b6102 5160 text optional discount_2.1.7-1+deb8u1.debian.tar.xz 11fce78b9e4efca01504f03d3ad3b818 20512 text optional discount_2.1.7-1+deb8u1_amd64.deb 190107301e109649e79060888bb59a5c 34312 libs optional libmarkdown2_2.1.7-1+deb8u1_amd64.deb 134200721772359d16a588c9f5cf0b78 21710 libdevel optional libmarkdown2-dev_2.1.7-1+deb8u1_amd64.deb 0f606f1e2ba1d2fdbbc5a02ef8b71584 67360 debug extra libmarkdown2-dbg_2.1.7-1+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAluUJ1VfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkioIQAK7naVAgd5iV5EZLVqj4JomEpZBrJAwb355F rr5c8uyP6drnK24gEcNmx5JO208ld2GsFeUL+t/jS4zZqEvHxzdilUzF6GGBLz2A ayhTBpUypMOa7t5t1dRBkYwnFSvdhSQoc4yuqD/GHgFN4fiu/JQ+zTXlGZK7msmq bH1Hnj4ZNQtFDeFsNaQBVr/Jn1Uqajx8ijrzzaT4PwnXGJYSOKKdzclM3nKHaNgx K4Phdfr99aQFDbQZ3/R/PTcPw+qQh+XE2SRgIutGVDQN2cqdzISebOjldKYDoDHE HFhWSlMOSsuUB6ObKtA6pFsaxOEwVXe2XpCb3l4QdIJWF+LikdJWniUHF3sVA/g9 Z/XGFAkutia/Hpfu4ILISVnNP6PjJIpSNDeRP/Q0qGqIAXYmjyeUNiFhtwFYUJPD 0kwdiSIy96RIAGkY+aj6pFPxcxC94j24DHmBdNxZz1BbwQibv5uLpKVDCkClDIXy dfA6It1z6eluskOYNmKEdfuHK5fXtzv9LbACxjcMWW9qlS8ZXLW0+SnRN71nP5cg 1w7gZEYajYOtSSrSbKh9eCuw/Q78JRtzznoJ73LbYlaN0SENcORrUb3HCQKFM0ol e2EQ/Gu+gnRNAv6mi/nhjxTskQlEbUpwn84dCERVt3/jNH2lith7s6vyv/XuhgOj pBHzEsXd =vFyn -----END PGP SIGNATURE-----