-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: powerpc Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: powerpc Build Daemon (praetorius) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: bb70053d1ffa097942a1a660a8a6b738ea216d23 179172 libpng12-0_1.2.44-1+squeeze1_powerpc.deb 2489b8110203b20d5062624c92d92fe6c78b0705 271912 libpng12-dev_1.2.44-1+squeeze1_powerpc.deb fe820f14597a201b7bdfbb1222f0760689594e22 72580 libpng12-0-udeb_1.2.44-1+squeeze1_powerpc.udeb Checksums-Sha256: a8ba43aa24bb0abf7c2789913a81051498aec38beadd798b32777d24e0a3d239 179172 libpng12-0_1.2.44-1+squeeze1_powerpc.deb 2e8a8f810c8422b98e51715d2640433f347789da9f7ee96a16bb27038dbf7862 271912 libpng12-dev_1.2.44-1+squeeze1_powerpc.deb 0d0ff61fcd15ed1a5335d92d13a8210853f5fd6ec9b69c513c5a4f7f27bdb343 72580 libpng12-0-udeb_1.2.44-1+squeeze1_powerpc.udeb Files: c48371ed317ef963f43cb8bdddd5ed8e 179172 libs optional libpng12-0_1.2.44-1+squeeze1_powerpc.deb 910e7b04d3d5fffe846c7c1eec1e96f1 271912 libdevel optional libpng12-dev_1.2.44-1+squeeze1_powerpc.deb 1daa96efc9641ca8beb1d98e4153e97a 72580 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_powerpc.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAk4thmoACgkQXm3vHE4uylqa1gCcCe+UzePNBRoB6X8BBOszgCaV s50AoIGJH0pTpANUyu3qkd+CYbea3LZZ =QYsw -----END PGP SIGNATURE-----