-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: armel Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: armel Build Daemon (arnold) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: 6969a4b1e2eaae0b0ae8c0ad5ba90d0f7b1b8f8c 174676 libpng12-0_1.2.44-1+squeeze1_armel.deb bdb75ee916b9a85ce700702bd9ed060a832d9197 262406 libpng12-dev_1.2.44-1+squeeze1_armel.deb b9f2b0b35bac1a38bf506e4e973ee19a5c35f984 67926 libpng12-0-udeb_1.2.44-1+squeeze1_armel.udeb Checksums-Sha256: 7773e1c1dd5d95d832d7d16f3c401e9119efd75c3dad88a9e8ce5f0dd7646dd4 174676 libpng12-0_1.2.44-1+squeeze1_armel.deb 9a047174fb28d56cc9d37fea1931a7088f76cfd8db2a20199a5825fd19b2be55 262406 libpng12-dev_1.2.44-1+squeeze1_armel.deb b093ed0284fccd54ba9af6a7d121be6992125dc2aabe5833057273053fa6c89d 67926 libpng12-0-udeb_1.2.44-1+squeeze1_armel.udeb Files: 6f6f195e2864c75af4541bcb7aab727a 174676 libs optional libpng12-0_1.2.44-1+squeeze1_armel.deb 8c269c5d7aa9981f1baf42813fc7bc62 262406 libdevel optional libpng12-dev_1.2.44-1+squeeze1_armel.deb 254ce9db12a8c756d24cdc2cf5c0d091 67926 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_armel.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBAgAGBQJOLY1uAAoJEJvVjrQ+qbowfa4P/0XR6A8LSrSSrE/Wzxjjp4hP MFNOfjvxbhkv7AywG1hDCaw3XlpGQ+sD/mlDvlj8jPZsq8jJhJBcu5rYjhfqLYF2 aTXBP9kSwvAowhLWVMa3Kf76TFzXPleojSOliROdZoT9Mh6viYDrnb+RgY/pEVYU br7pI36wZMBuLde+nQqGgc1XV4JxWTtrpeRvGJvq9lUPXydFjfzjRaRH9ohh7K8F 0EhLsQdkhXAEnj3jIG4WJEgT02VVJci8JW5f4O1UOGRQ5k5m6BSdWEob7I4Y6y3a o4BT5IWFTV3slahMrZeWnYqbCdQtn2tZrIWCmxflvSwThyeN8ZTsvcgSuUzLjDlB GcOLRGo/p+qciWc2iKLfmBZlreI4tAlWbEyXu51dywGG0wsmWrRGzYkq1V5VWjth BNTi2H3agLPfWhSwe0fRvhsSzBNdjLAAYFFdBanlMVdUa5EjO09einGBS+ru4Tn2 8m6mTqAkrjHb9z2Yd0Li/opoaKT9DRqBrz80J05VXlBZzIyr9mKvtVLdAQWQch4n QWjuXm9UFDBMdP40H185aLp05mVq6qFd9YKQDtEVLzmuuuG2YtrdRzOa8Mwr4Hu2 N5RMbXgeUhsXSqvNzdRyRNRPZY36cdyhTCZOfuClpnHowffqjTwp5NW/laU52xRM rxI3ROER/dGW40/pMrOo =UbmG -----END PGP SIGNATURE-----