-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: s390 Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: s390 Build Daemon (zandonai) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: 3cd663deb13c45f13c435275d7efad3bbc924edc 181482 libpng12-0_1.2.44-1+squeeze1_s390.deb e98f60ccb46029550d72ec740cd092a54047e0a2 271564 libpng12-dev_1.2.44-1+squeeze1_s390.deb 90ed681e2b179caf52b8417872825e6f0f220ea6 75154 libpng12-0-udeb_1.2.44-1+squeeze1_s390.udeb Checksums-Sha256: 0f0a0e151a737deec3f6ce5cda2d9b888d4c28b2e9149f56031d4685758239f4 181482 libpng12-0_1.2.44-1+squeeze1_s390.deb 4006ec3618cc5477c319c772614b5740168b37a3c503ecad4bb4d14085d6474a 271564 libpng12-dev_1.2.44-1+squeeze1_s390.deb be2c9fda127d8504b6084c9902769ebcf8d1b93c495731b5c525220f2ba7ae19 75154 libpng12-0-udeb_1.2.44-1+squeeze1_s390.udeb Files: aeeb12caee1e9de83a04949fb2fcfb66 181482 libs optional libpng12-0_1.2.44-1+squeeze1_s390.deb e9642b410324a3a10250cc832e8a7c68 271564 libdevel optional libpng12-dev_1.2.44-1+squeeze1_s390.deb 3c38b679629dfc7f7474685c5a136f2d 75154 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_s390.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJOLX1MAAoJEPaODSItlB0mmccP/jnjtdDldXrf8yrGVR05zq+v PM/XjpTqjVanb9Q9qdisVmxI6WiwmtNor6oVE+D5e9VXLo83kF7awdaKl6/3qPCF Kl2EHUk2s5rLtqgbDN94gG9i4XpvreFkNWGWCipvjG4xk/jzeKz2nObLJiRoagfz n9ChdU+9+MMD2Fhl7L/eIDXjCpRCHKn2rmBCVDWYFjr7+Y4a6NnEL7oN6EplWpF+ KDj4Mt10bYMFcH7gczXFrm4O0JO2ds/PHscAft6P3WvvBoMEEKJOGVaWTwcuoCfl Xfusti+XTEV+qvW2Qws0G+BdsL4sMqeiT/9YdWFogKifLoHN0I4RHTpi/b0ZQKFY sdvrGGrf0Ni0UrZ+7KGEu+fY63xHcmUBvbtNWhdXwMZKFy4XrR3uql6bRXy8L5bN /1Ouq7W0FiXxcQlwDSAY1YcTT4sguFnWXuG14RLVX9hK/6rUejbQ/B4LlVL32C6I zOftAvHuwpDInGY5TdqdZbVHN/RF91fqYhQERT4IjtJJN7VGcvl13ZcYkHrYSSvM RyJIlYnaQJEtpwloVww8uNUJ6LZUzOhXVa6DhAz2eX9zH6+5ThjWoXjfvMR3T3Ha 9a1i7G8fnK06VzJuoqX6sLRb03tPmHpKoEeSENsRm36JKdgpn7jxcVJxbseOJM0S zEnzFf0renuUaeaROBHw =yfRP -----END PGP SIGNATURE-----