-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: ia64 Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: ia64 Build Daemon (mundy) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: 2fd966221bf52262df45521e6f42c5496e595b68 222776 libpng12-0_1.2.44-1+squeeze1_ia64.deb 7ba3992a96d549e64587ad92a19015a9d19b5e11 324276 libpng12-dev_1.2.44-1+squeeze1_ia64.deb 0b69744bb63fafacfbe6ca1c2f59d1adc6511d4d 115760 libpng12-0-udeb_1.2.44-1+squeeze1_ia64.udeb Checksums-Sha256: 37f4067242ee74866cadb7cd7d5fe40ec7784b85ce405c16c44d343d857488c8 222776 libpng12-0_1.2.44-1+squeeze1_ia64.deb 61e8b10a1626b6230765eea0a24ff537b447cc06eec7a408647637a34c84f778 324276 libpng12-dev_1.2.44-1+squeeze1_ia64.deb 8563faf7cd2eec589d0fe206ca961974ccd1fddc40f1156f13468c6c54116417 115760 libpng12-0-udeb_1.2.44-1+squeeze1_ia64.udeb Files: f002f52a1f4c369b6f4c2bbffc5d5746 222776 libs optional libpng12-0_1.2.44-1+squeeze1_ia64.deb d3387aef8c8eb94607cd42eb3e5be8e0 324276 libdevel optional libpng12-dev_1.2.44-1+squeeze1_ia64.deb 291accf7267efbbd5c555e45baf6807d 115760 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_ia64.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBCAAGBQJOLXwoAAoJEHzOw5eW+kj06vcP/0yDFFySPSmY2qVB+Bnx43hK g6XOAlDcZfbuqrAfM6TnQ4FOIz5Ip1x2aJrxBu8ZeXqEWJYPBysUkENoU+UxuJ4m TW2uD59c4/hFNziDSRZ6JUni/UAqzklAhE/KLrT7uo+rC6LFUoAWrLzuKJ66Y/3n vyQbMijdzbGeXN+J706vHbiVFa/cBjQ/FWXgiDRSqo89Re0vIM8PfadufRF5pDh0 aMdY1clsLlf8ykP19q+6ndetcHzxOgsQyX3hmG6sQoHuz+AEZADUt0iIZLQdYqfY p8buF9G8PdvU4U0yQbh224sagaWEaNGhY4u3NXp+2Cik4gZn2XweWfbyIQz89FDL pBC9+prhU+furAmnlEDrV2cvrujyVMwup9XEpNZ43yub13q2TeNSRCN8+GVba8sB EILPsLssjqHBWTGEHGTAfU0vDgZQYsN4i2XbeA4ZAHwiDl2wV8ZbUITlDrSgIG8X 92g+INnhJe9r/U5iKzBTctzZ6qm3gCXICHrR4VvLcj3msyaiPYLtWQnaKJWzu67i lFZOG5/5gv+v4MFdwPEPTEBVWZUGO8+iUsGT8ocei3+jo8jAfGGBBOHmo0dErV6u Hz1HZCHssqdpdXHfRlRzSdPRHuE3FTuKn6FZMbqYdLKF0AU2ZAbHmLOQARlaurv9 sA6AATcejfozkyj+6E74 =+Ns/ -----END PGP SIGNATURE-----