-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: sparc Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: sparc Build Daemon (lebrun) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: 7ba12d7f418ade619ced4aac23a5dbeecf00d101 175184 libpng12-0_1.2.44-1+squeeze1_sparc.deb 8996f56c2269f3e6e410358f0c4afbece45de978 265638 libpng12-dev_1.2.44-1+squeeze1_sparc.deb 0dda2697bf4a6a14c3b7b21a50ba41505dfa9468 68700 libpng12-0-udeb_1.2.44-1+squeeze1_sparc.udeb Checksums-Sha256: 5bd9da3aea7b65e175245235decde523facdb26e5fa8b5ea5886cb9a515a4c61 175184 libpng12-0_1.2.44-1+squeeze1_sparc.deb d6fb45189b2d9d7a7608784c524a5bc33536f08e7fbacb9191af56da28b97815 265638 libpng12-dev_1.2.44-1+squeeze1_sparc.deb 143e79e48702240913ce92f1dadc45172a48b509c46c4cbb4c2d69d81cf0fb46 68700 libpng12-0-udeb_1.2.44-1+squeeze1_sparc.udeb Files: 5af78a5a26400cd362d717417e115e3f 175184 libs optional libpng12-0_1.2.44-1+squeeze1_sparc.deb c3564d967585f1961995daf95c3c53e6 265638 libdevel optional libpng12-dev_1.2.44-1+squeeze1_sparc.deb 3a3d14c41b902221d518bd996251cb76 68700 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_sparc.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJOLXuRAAoJEMSeX6ljLj22mGUP/0K3yvSvEi1+3HInu5A+c4cI AX+6epAXEAkSLM6s18F/z3Ux3tsjgfmMKW0PBvE7pv/f8R6mXf47avmGh6E6ETG4 Pp0xAeTNEBQLszBKGljPhF4Sh8Uv7qrgZU+xQjFzvVzL4CUiIoOQAkYkUeIYq4n8 iKlZb+EmpkssnJ08X1wA1SXEIfYHnR7hT2XQ9xJ9eiGwVcH3yLl/UfJPHo4Bllw6 g0fjhBtDCbstYur/wynIW+c+wm+8IKGzQ1lnx8TX8/mWqgp4qD0Yd8y+uphI7nMZ coaurNIlxZVosri9LqHBJXkQgbebLu2aI2O7vdIJxlzgkZ0yg7BAwZ/5Qg80iaUw OSSuIKs+Ao7GPwU+HOmwRqjipgBGNMmbJxlQ/ZzNMeApM1XdMy6CS1Cd4aICFeUo 2OsLDp19Ct3V0TWXgz20k8/6NCKkSNJEUmad8UCODLq4wYzIcf4VRCeR2oT9m4CJ S2wFBuOilcN9KEBFXftjkY8p/TOtJarsWhMG0CV+I266jUbR4XlUvERUu+Nni3WC kwl/K4z880WQOBXI88ZdibZazQqrKcreN7I4MEeNWJbjI17vllodhFqj3MNfKVAc PbbCAts2Cvh5ogr8sMJ0RS38KdnuAi4A7wZFj5enzs+QrZngcf11FYj3M/Wm00Jb AkxCQBBgbmZ6tJCoPUpO =BBfD -----END PGP SIGNATURE-----