-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: i386 Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: i386 Build Daemon (murphy) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: e9a2f0c5b3b994bb21a9bcbdcf86c30bfda2601b 176250 libpng12-0_1.2.44-1+squeeze1_i386.deb bdef57538883df7ca233128d2e6ce7a89370f9ac 261358 libpng12-dev_1.2.44-1+squeeze1_i386.deb af71041459fc2f214c7098195db7612c1e8be91f 69954 libpng12-0-udeb_1.2.44-1+squeeze1_i386.udeb Checksums-Sha256: b0a9e27194a67a939898099ee629c560262a00d4bb79d8aaac37c9d751d80e01 176250 libpng12-0_1.2.44-1+squeeze1_i386.deb 79de9f3989703ef89b785173c38f53f57510a22507d10c315b0dbab35edf4dff 261358 libpng12-dev_1.2.44-1+squeeze1_i386.deb 0b3834d2c6a25ef9680b47b50056c92d85ce23613f7f0de59b0908a347be7af4 69954 libpng12-0-udeb_1.2.44-1+squeeze1_i386.udeb Files: 78c00496ed8bd3c40f75bef54b307d7b 176250 libs optional libpng12-0_1.2.44-1+squeeze1_i386.deb 6632aeeb8cca99d3e4e055479653f289 261358 libdevel optional libpng12-dev_1.2.44-1+squeeze1_i386.deb d94b1398e09e2d1c9983140e0b06b595 69954 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_i386.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJOLwvkAAoJELdq5EKse8nB++AQALZEBTikwtePD1xlp+wO3K0b sW7TWomJYA+0zDTU5t2S8k5sUPsaUo1kWW9tyvLGpMD8qLzq1OwB7llMfP7Mp1jV jTc1R7Qe5PwEiZurp12tsrfCMk6ECD+0ORtz8fnCrgcrkoytWYO45wB32MuenFsO D2+adnGIreFJg25KhjaIKYQHncg19jbcH3XtbRwhs9vE/SS96+2yqf+0L3oMKdh0 keV8+KSu6tJu5o3CXXUuGEh3ER/0/MCbmsnYdg4Hyso4EVjwQokSrdgF3iPUixAb AFTvNGRmV5Z3sZtjJY6BTMUhlkv2kTXZgJjD1+KXyJ8/TOp7rJGbN/Pfrj8Dpu8F XzCTR/IKxHHkjatsru7K0mIZiCVeufIRIkf2nBXR45biVij0BLnR5Wwtx2YxI11O JXFU5IDuCFMGt7bEv90KrxsEVBWr0HwpXlYawkNi4zHUzL1kXorfURtmBCgo3ezK j+N2JrWsj73dTcLTQtQHtYRSbq1I0joRVpqyzCnMpXTTc4DaRYk4zW6AP4hiygiO kBkfzdGM6XuwwwJS4sgLlLr5yBf5qKd56FN12Cb0EgSfXwb4vZqv+oCw6JAYMosF 65Au/b1FOGSolBIkMKseq+OKdzY7X6WdDHQfoLxoW3KAbAXylo7+IW/w2xnvzNH3 C2IIYTCd2EPBhtJ12mx9 =EKTx -----END PGP SIGNATURE-----