Accepted libwebp 1.2.4-0.3 (source) into unstable
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Thu, 14 Sep 2023 17:44:43 +0200
Source: libwebp
Built-For-Profiles: noudeb
Architecture: source
Version: 1.2.4-0.3
Distribution: unstable
Urgency: medium
Maintainer: Jeff Breidenbach <jab@debian.org>
Changed-By: Gianfranco Costamagna <locutusofborg@debian.org>
Closes: 1051786
Changes:
libwebp (1.2.4-0.3) unstable; urgency=medium
.
* Non-maintainer upload
.
[ Marc Deslauriers ]
* SECURITY UPDATE: Heap buffer overflow in BuildHuffmanTable
- debian/patches/CVE-2023-4863.patch: fix OOB write in
BuildHuffmanTable in src/dec/vp8l_dec.c, src/dec/vp8li_dec.h,
src/utils/huffman_utils.c, src/utils/huffman_utils.h.
- CVE-2023-4863 (Closes: #1051786)
Checksums-Sha1:
ae376370cf5af552dae5f4bacd56462998966e44 2379 libwebp_1.2.4-0.3.dsc
024945f296f435689a3f866a6aac74e0ed50a4a5 12004 libwebp_1.2.4-0.3.debian.tar.xz
83168a2c666b48f00c89f8a9218bc4bcacb65d47 8332 libwebp_1.2.4-0.3_source.buildinfo
Checksums-Sha256:
822a6258c3d41b875a60e709c46cf739c55047b4b6d0e1541c5432a4fe445ec8 2379 libwebp_1.2.4-0.3.dsc
e2196110d735d4020feefa38ca28abc6e87a3998c0ce9645dbc8745ac64dc20d 12004 libwebp_1.2.4-0.3.debian.tar.xz
2726c5aef385361ea9ada8e518073f22c98ffbbffff2e733745d0ab13b4faac2 8332 libwebp_1.2.4-0.3_source.buildinfo
Files:
7f4d117d960f22180d0ca71da228554c 2379 libs optional libwebp_1.2.4-0.3.dsc
5e73b5b54e7e3f95350c56fe095a5544 12004 libs optional libwebp_1.2.4-0.3.debian.tar.xz
a1b5290e27af3d4f7016423c2673b7dc 8332 libs optional libwebp_1.2.4-0.3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEkpeKbhleSSGCX3/w808JdE6fXdkFAmUDKssACgkQ808JdE6f
XdnvZg//cIjSJTR7EB9bg4w2TuiIrO/S4gu27YBv2f81IE1ov7sa+44tMEbpKElx
wtQw4hI16JiwiE3FLOjAZ5JmW2ylTZ4pTachsewP19Lww351go9hlLlHv7ZqiL7F
1+YqycVuL3m50VAyN2lKIMbD+Y6wQnJeqhjvGkE6gFNIAx+Q4zLPY1rw+qXWIhpo
WIYZzMyrtGJtC/BrIdb+m4XvXjIiqzbMULT/SmbziRfQOFmtXN8aHUD9LqcFjAKC
EfvT7JWBbpPt2Z0G7vIsEvzFrdRkwvfiXqW+DfLK+/uh4uDHtZBa+tcpkgvVRoeF
j4VOWkMYx354E3RT82yYvyp+kescXNK8sg6+HwkjdHtP68I7rP257KjX2fIJ/y35
TTNNs98ujZPDP+EApeKEt+JhaZ8OP8Fs0O4xuaoo9h+ad6bQWJwSHpwxmh6xjGa9
ZmZ0Kyue+gtxSolrWp4g4nT2j6CYcqWRM1G1wnUh8knhMnbpz6fVb9IQdo24RAS4
Eha6sCeHJ7mGZ9rH2SeJcRwc6sGiVvwMnjkqZnJIQQ1X3A9YgZwsDeA9ze/v2/eN
uDNIDr8UcHw3d1vdbUtrqq1grCFNfCiOkfJjaFX+sBkKxZtD5y/wHuSLQZcq526Z
iRqve+DIU2eSxATofKhmFBHNxjUfsdNFcoeAPmdksiwAV4TUhEA=
=TYMj
-----END PGP SIGNATURE-----
Reply to: