-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: kfreebsd-amd64 Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: kfreebsd-amd64 Build Daemon (fano) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: 83e7c54522156c544081b1f7039c7d22b37ec10f 180388 libpng12-0_1.2.44-1+squeeze1_kfreebsd-amd64.deb 91df50dbdd71c170e52dd8a29bd791176d787726 272608 libpng12-dev_1.2.44-1+squeeze1_kfreebsd-amd64.deb 113b60964e91006dc6c670630577fcc6d636dc14 73890 libpng12-0-udeb_1.2.44-1+squeeze1_kfreebsd-amd64.udeb Checksums-Sha256: 282aa0932a363146aa53cd5842dc7ffa2adf3f1049ee6ca59299d01cdd75b9ed 180388 libpng12-0_1.2.44-1+squeeze1_kfreebsd-amd64.deb a9fb35dbd0501aa41d7d3b67abf20bf8f4a0ca6ef920ef56f603135810dd555f 272608 libpng12-dev_1.2.44-1+squeeze1_kfreebsd-amd64.deb d73b8945a45b9b7c4e569380776231f994a38fc1187052d73888d1baaabeb2bd 73890 libpng12-0-udeb_1.2.44-1+squeeze1_kfreebsd-amd64.udeb Files: 3623292d2865fc254bb7e2be17d933ec 180388 libs optional libpng12-0_1.2.44-1+squeeze1_kfreebsd-amd64.deb ba6b0ff75742da2982c284afbfe72c9d 272608 libdevel optional libpng12-dev_1.2.44-1+squeeze1_kfreebsd-amd64.deb 5e881215760c5c671719120d72db6470 73890 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_kfreebsd-amd64.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/kFreeBSD) iQIcBAEBAgAGBQJOLXxJAAoJEDc8dl2RHqtpjIwP/iUtRxDb4R4a7dLuaXQR/bRQ KUA3xYoZuvXXrhqCtxe6vz8G9oOsOLS1jDfl1NA6H/dT5aV0+0PqCfn/OLoXHi7H ehez6nBly88B/t+iETM7x7XjcrUDucl8GNu3n3r76HyYuo4gNxPgYIq2Pm/789pS 49Qdnrq00EQx/plAHu4agEM2/VVQAf+zk3U0YoggDJ//fkjzEhoCmwcnpQyYCwpo GhZ7jmAROHeQcPJH8okp/OgnfNO1ulFsPk/Ww+RG4mAv2kZ/khUhYdRUim10wL4y /t7rgOnRkroMGGbgjli3yB5Qj/kPD4jdklRxPCnoTswoG6JawHvnqHQOwE85GytA 4Gr3ejEWngWapmOZM03CRrPw6HCcAPIMaJU73g/gDSyA9enfn0Wi5VbpXsKA2Nj+ 4IqH/HiFbCbm83ZvWmsQOorjaGzHHu1pu5WalrwM9Si6nfj3OtlzTR6JNPk+hxmd aVpqG/+pvL7zH3FgUj6vh4xEUJXdlDGNDW239x8EfpPkc26pO5DUMFaQ5n00zJle sV95ZqIZRTDVKWv52iiSDvfdJHDBwEuvEpN/sJmyzbvnab/yWLRecJ0Wrwok7+na 38wCtqr3WQn5H9f2aTFLVkhVi7pekwAXn/tui90uvyp9gmPvBPwF9YSapHmliZ1T jsbEqPbA8il/B9bU1p4t =kI/6 -----END PGP SIGNATURE-----