-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: kfreebsd-i386 Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: kfreebsd-i386 Build Daemon (field) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: 0a483f5fd4e8c790af9c52207f8627e363c8e63e 176226 libpng12-0_1.2.44-1+squeeze1_kfreebsd-i386.deb cee61d44b23c244a7a6df27d0f3a48bfdee64869 262000 libpng12-dev_1.2.44-1+squeeze1_kfreebsd-i386.deb d7b289d3168b90302abaf5af3a7033dabfc1a8dc 69908 libpng12-0-udeb_1.2.44-1+squeeze1_kfreebsd-i386.udeb Checksums-Sha256: c7034e5525f5324d32a0bf272aa3e711d33f8ab9ae700d4261c21ed2d3ed19c1 176226 libpng12-0_1.2.44-1+squeeze1_kfreebsd-i386.deb 1acf2ff5a7e3ab9a3c243c5896376c751940558e3b029c6e898c7cacef72b4c0 262000 libpng12-dev_1.2.44-1+squeeze1_kfreebsd-i386.deb 312dda081a1f463e6c9dc3aaa24095b2ed699132579d8265e1001d4b288556f0 69908 libpng12-0-udeb_1.2.44-1+squeeze1_kfreebsd-i386.udeb Files: 400fda9cf766f4207970e6e9bed41642 176226 libs optional libpng12-0_1.2.44-1+squeeze1_kfreebsd-i386.deb 01d1100626cb3e380f60fa2a5e38cb78 262000 libdevel optional libpng12-dev_1.2.44-1+squeeze1_kfreebsd-i386.deb ad0762304322a36e2fc7ab476135ed19 69908 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_kfreebsd-i386.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/kFreeBSD) iQIcBAEBAgAGBQJOLX1dAAoJEEL2rX1rgBbucXwQAMuRU2SUran+J3QOFZP3imrU 57vtCxnXpgMv546WOgVg7B9xV/Jp6XPQ/XRu7K1LyFjuU9lnfXE4IThzkjRRqKsG cp0ny7SHI1ta/8BAVxp18fMQpXFci9GV6w2bUSCRcr7k2258HVT0z5inDNmIUxdh 27FZK+I0I3lTTEe6Ed/5gTNKt1Ffs0LZjDxT0uXY3aEc+4C53ysHV+rr3TRBF0GH SyXUEr1eOj+re4wqn+0BTRuS41NFMtGwiqNnyjzxflL8uqkDap2hjvJeqrzVUoGc EYt/fpN+Z19/Jl1e/zFFoloZ9pY9afYwVzuvuhGqDATm6MHnfOHfdOM/q9uvma0U hsq3EN5r0nR7kNcxScdiS8JnVw/Fh9rrZcfv74bju1VFc417uNvanU/TvLZ51ROq 8P/91bz8U9Dw95eJ/idwIuMuWaS+bnFMB5wDutPX9CMkRDPb2SPyjxe7tuNLJNfQ HRylCPxofp89QgSF/xdJ4Mc1aYttJ18szDa2D6ywntC1K1GGnqXZyZBGDIMha7RI 9B/lVct2wDO57eGvJhSLgn4yDUUKqffMMv84VUiz2NaxKGVCiCYOwoNlv8luuCI8 DGcPpYGfqYrXfNoL/7CALlF52mS6s+CvNhGew66zbrGLSz+EnjIsh7U4D2Yg/xoj W2rhJPrzhnXQogcjW9IQ =u2+M -----END PGP SIGNATURE-----