-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 15 Jul 2011 13:06:17 +0900 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: mipsel Version: 1.2.44-1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: mipsel Build Daemon (mayer) Changed-By: Nobuhiro Iwamatsu Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Closes: 632786 633871 Changes: libpng (1.2.44-1+squeeze1) stable-security; urgency=high . * Apply upstream patch to 1-byte uninitialized memory reference in png_format_buffer(). (Closes: #632786, CVE-2011-2501) * Apply upstream patch to buffer overwrite in png_rgb_to_gray. (Closes: #633871, CVE-2011-2690) * Apply upstream patch to crash in png_default_error due to use of NULL Pointer. (Closes: #633871, CVE-2011-2691) * Apply upstream patch to memory corruption when handling empty sCAL chunks. (Closes: #633871, CVE-2011-2692) Checksums-Sha1: 054b958fe1435f6eac7a685e59f7344c1e3e3a06 176754 libpng12-0_1.2.44-1+squeeze1_mipsel.deb 1dca0526fa8f1a483f539912dfe574d37b93567f 279346 libpng12-dev_1.2.44-1+squeeze1_mipsel.deb 2879ade3983c8e4478e4d8668eee5e30fc26eb17 69976 libpng12-0-udeb_1.2.44-1+squeeze1_mipsel.udeb Checksums-Sha256: 379d8d5ccc362f938adb4f24efbe7256337ffe6fe41d487dd7fb3a31e3a9b6d8 176754 libpng12-0_1.2.44-1+squeeze1_mipsel.deb 3e38f296f99697f8ebaadc2cec71fc65d6eff840159e2d0249ca17093d13a4e3 279346 libpng12-dev_1.2.44-1+squeeze1_mipsel.deb 315be7c32c7dec94cd46ef22f0399845649fd5408bfdce95cedd9cfb98bf2042 69976 libpng12-0-udeb_1.2.44-1+squeeze1_mipsel.udeb Files: 1b80f2105a377e1323aa1f04090c158a 176754 libs optional libpng12-0_1.2.44-1+squeeze1_mipsel.deb 1500e4928a443fbacdf368ae31f720b4 279346 libdevel optional libpng12-dev_1.2.44-1+squeeze1_mipsel.deb 2cf21d9ab987727c9eb9d3d730f7cf83 69976 debian-installer extra libpng12-0-udeb_1.2.44-1+squeeze1_mipsel.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBCAAGBQJOLk46AAoJEHR+3TSlYz+Uiw8QAJ8v0WfYb2hWuOm/fzIciQNk FCLM2XQqohonV6XNRWdoGXcEkSeQ2TzNXIfC5zOKwCWLtVBM46oSgt9OlNlH9vuE /Pzd/QIFQ6zSZuxqn8KU4n+Z9x3wB0X/YCZEQIzz3Qj2bN1dlNjSmEzpzhAw/Fth YP87mjOpOnNiUDfd+922UNT4bvmc3IoiPKN3xKJynUKiLvQcbnl88VOwD4/aBPvH jNPl8rOoHrPlkv5cTDQf0v9ZuVhgUTrIPgWbD3hSS7gDK1KTiN5L7HTaYMKRo1VC yCpQgIPgk08R+X7KIlKUrM6E0PN3ZxHE36H83rFRY6htrCICMyBvtEyDlXRpKAVe YxYuxrSC6XfExh/4GwmDvInafM9dBiHF6O4OSFmfriSSwbbjZCN/r44eDFDUUkfm BpQN0xk9SyrC3wxZiP5gN7LCA/UhAShg4wH5/Ehar6tMyJ69Cu2mXorqm6xLy/RO SMTFRMRnuDVW8QfrGK2jIz5ERcWy3+TQ7+lWP6/zKgoCB2ebkHFNKowqTY/1xuCt YRayfFPlDEWOC8gE/NWh/TDTNXm2BowhEtmNfZWaw5r8bybg3/N5hZHNxZ/haJng mljlDOlG7lOHi7Q7NV0qh/JipItDR/K3L1aJwd2GWaV5vTvG2vL20f4EJUOLn/eA O1JSh9Vd5oEkFwiyVy2a =aw+f -----END PGP SIGNATURE-----