-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 02 Sep 2022 20:01:56 +0200 Source: gdk-pixbuf Architecture: source Version: 2.42.2+dfsg-1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian GNOME Maintainers Changed-By: Salvatore Bonaccorso Closes: 1014600 Changes: gdk-pixbuf (2.42.2+dfsg-1+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the Security Team. * gif: Check for overflow when compositing or clearing frames (CVE-2021-46829) * Add an assertion that checks for maximum LZW code size * Fix the check for maximum value of LZW initial code size (CVE-2021-44648) (Closes: #1014600) * Replace GIF in testcase which was broken in the LZW code size, not the values of the pixels Checksums-Sha1: a056d60edcd0472a910f434a5a656dcd2481167f 3341 gdk-pixbuf_2.42.2+dfsg-1+deb11u1.dsc d66fc4f6f28e3cbdcc1bc8c1b25495c7c6fd6c3f 6433920 gdk-pixbuf_2.42.2+dfsg.orig.tar.xz 0f3cf8e6e30941515412e585fc76e62161b4dbcf 30792 gdk-pixbuf_2.42.2+dfsg-1+deb11u1.debian.tar.xz c2f7afb57b42eb3bf951201eea26663ea2bdbe04 7443 gdk-pixbuf_2.42.2+dfsg-1+deb11u1_source.buildinfo Checksums-Sha256: 3dbe7c7fe9455692b167195af6ef39745bfc060dc3767bc5404d286b65188fdd 3341 gdk-pixbuf_2.42.2+dfsg-1+deb11u1.dsc f781dca5af4c6536befb1faaa3b82efb9750c52a350842bc82b2aa08ce129ee9 6433920 gdk-pixbuf_2.42.2+dfsg.orig.tar.xz e1ca8800ec1be85b0945c4da4121d2aac176b67b4cce99db5e6d34ecedda3db4 30792 gdk-pixbuf_2.42.2+dfsg-1+deb11u1.debian.tar.xz 3fe44bd6f4af5a24c37b5875f11235f71416cbfb2a5be7413ecec5670b79d6ac 7443 gdk-pixbuf_2.42.2+dfsg-1+deb11u1_source.buildinfo Files: 5166d976aa3dc5cba655a27871b3b917 3341 libs optional gdk-pixbuf_2.42.2+dfsg-1+deb11u1.dsc 6ad51a9ed2b394acc88052ae9de01c9e 6433920 libs optional gdk-pixbuf_2.42.2+dfsg.orig.tar.xz 6124ab78e2698efbe34a6eb52353a68b 30792 libs optional gdk-pixbuf_2.42.2+dfsg-1+deb11u1.debian.tar.xz 511f0a16eaf6cabc7e8da16bb914d47e 7443 libs optional gdk-pixbuf_2.42.2+dfsg-1+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmMSS8tfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EmYYP/30y61IWM8A2KtllMTJVavF2KVmkYawK DuyzHKk5N5CI+5GYch96OeFK+lUv2o3qa7QEA/1UFlmb3X7gJDTB7Ccy+FDTHlWF busWZ4/v6VZh8fztUvSWKTzRJT2xY45MaCMtOAKT8VAKSzzXuFmwh3lu1LimzTGR WvInpiSEuvZ1hS1Ufj78rQp6LI1VaCN1UWR4yCUnfEOFm+FRij38d6tfIwuS+TD2 JNgzMinmMFDVIGByNh9QexEPwGIytlfXTLfjlK4ri4JEw7IMlSNyi9PND888brLq Vml/hXuAYZPfP0bjq4A7RWWvgqii1sVQfz2oo6xwXEDX6+B3ohn5qZnaET6Ughjm 54NgGgcDgnxghSlTEaRikHDq2Bku94Svvo7daFk41MiHpnlTuJ68nDF8Qu6qYGuC pQ9rcNc4GYRRFzIVjf/RqR6sX/NS5259WlDdXmxLydM0n/mdsod75GXLWrs535tS zmnF8gUGSVIm/xYn23jJt864sBBkgqLjnNJRp64I0gB20g3vjzBfDcqY7K6ug5ru rFrmXPoS+vZ5lGdw+8g4mvVm8rdNjcU9+DX0M2lg723yP0ODynz42s2wnvM1P4ur +T0uqScGNwX6fiTnb7eDsPNhh57WreDdHwJA8zw8GIsNyPCmVlMoFWQhdzeFlahv 2UFnJLr7DyQS =0cVw -----END PGP SIGNATURE-----