-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: mips Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: mips Build Daemon (lucatelli) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: 27968ac9c71bf147175db964f4422b85e887a392 176578 libpng12-0_1.2.44-1+squeeze1_mips.deb a752cbc96e3689496e2cad710b88edb08bdcdca0 279462 libpng12-dev_1.2.44-1+squeeze1_mips.deb 753ebb04b7a3ec0cb33a288710f4b1e76091b7b8 69858 libpng12-0-udeb_1.2.44-1+squeeze1_mips.udeb Checksums-Sha256: 4f4f48c95d27b78c995e3ad11e95d49060c3be876c182bf327e232b770fbe2b7 176578 libpng12-0_1.2.44-1+squeeze1_mips.deb a4b85d9b344048cddcf6e6477dbd75dfe067393a3fcc4a895d10a1cf1d2bd496 279462 libpng12-dev_1.2.44-1+squeeze1_mips.deb fafd0e5d6d1b1d734f692e5e7aa4cd0f7b8a33239ded2a777ecebea2215df61b 69858 libpng12-0-udeb_1.2.44-1+squeeze1_mips.udeb Files: 869b7c0d9cd31a915dd8c101188c433c 176578 libs optional libpng12-0_1.2.44-1+squeeze1_mips.deb c1e7cbec378cb6cfe0d6e0cef9b729a0 279462 libdevel optional libpng12-dev_1.2.44-1+squeeze1_mips.deb 2cee67e491a18d82ba5b2fd49dcd0430 69858 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_mips.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBCAAGBQJOLX2RAAoJEATeXoL9/adqwZUP/3BuqsO0Lhm0gXG6xaUEVBFe WapPyEn8yhoWCpcP94cjuEhuHANKJVoHFuEOjFHqpaHOL7zaYK0KgBMC6QZJyrxy DoKNsQ8cbho1Ls5N1kMEQ8ZLvHN0sRK8jGTlqB3Z1Z7GibHQEO2JdfXDhfmyb2je 25SCnYxp2S1Lbt3+dqu/6xBjc/XGSjTP4YUWXwPSzP0+m96LaTrIH5PS0zHAP4zr 8NZCxN9o8cnJNm3B8WPWRAEfe3KP5jXR86yrk2b33Thq6+IW5KOJw79c8O25jnIP g+vpMi6x3yHu6CDUZDhh5y7tr4Hv4Y7MOuV1oumkgotB5tRM8mj2b/fyLQIoTVlF MfbeLyAWler4zSDbgmSFnCGvnD+8uWcVb0dBTtNPCwZ0hDk+RqNvoJ+q+uLespqH zZnqPb6TvzS23+lyHuDGDUuAhaNZ569wfr3HEDPbPeV7MiWU/fw89LJR8zsp4SOf dLSobh39HWFRkFZDccbTPIr2qLjM5MfXluuyZW5vfEdiiMbD09sFZOub0dA2l8g0 JlS4em0Vn2bUjknmfG1s8STRBPv4Bnkew1UM7tny7FAw6q4v2EuhNiAVODJ6vQMr f5GKtvUmmCrnldZFd3CDEQwff0gnc8USZrwJqsqgQjAzlcCoI5khL3eIheoI/WCr YJ6ILZJB6UVUlJ2+fKN4 =YqOY -----END PGP SIGNATURE-----