-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 25 Jul 2025 22:21:17 +0200 Source: audiofile Architecture: source Version: 0.3.6-5+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian Multimedia Maintainers <debian-multimedia@lists.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Changes: audiofile (0.3.6-5+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * CVE-2019-13147 Fix a DOS due integer overflow. Bail out early if NeXT audiofile support allocate more than INT_MAX/8 channels. * CVE-2022-24599 Fix a memory leak by reading not null terminated copyright field Checksums-Sha1: 7092ab373325b514350df63ef60f58a8162a300c 2303 audiofile_0.3.6-5+deb11u1.dsc 3aba3ef724b1b5f88cfc20ab9f8ce098e6c35a0e 811733 audiofile_0.3.6.orig.tar.gz a22553598d62ed98adcc2fc80155286d20e4af00 19940 audiofile_0.3.6-5+deb11u1.debian.tar.xz Checksums-Sha256: c23883c69aab6c694e48e2c5a7a3a7ee117ec475869796d9371a66ce682ead08 2303 audiofile_0.3.6-5+deb11u1.dsc cdc60df19ab08bfe55344395739bb08f50fc15c92da3962fac334d3bff116965 811733 audiofile_0.3.6.orig.tar.gz a4d224c802286fe55f5c0a16d21a82d8bed7c69e96c9fd32ac19ed6c3458fc71 19940 audiofile_0.3.6-5+deb11u1.debian.tar.xz Files: 71b2928a7801e269ac364e87ed1a9be7 2303 libs optional audiofile_0.3.6-5+deb11u1.dsc 2731d79bec0acef3d30d2fc86b0b72fd 811733 libs optional audiofile_0.3.6.orig.tar.gz 392c61dae4fdff509a0cfbd7a642a340 19940 libs optional audiofile_0.3.6-5+deb11u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmiHLBlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR7ggD/9FstQGrtEBAdUtoBzk7ItNlnW/HJ88 +6nH0TxUMt/tgCHUIH3j0vdbRNS9HICjVqs8WULcyuJ35SSEIuGY9Ozz2yTgfTyt O72VPXYO9u9kb3L7ZoroINH9YnBoy5tbh4L1GYyHkrrinEVGCcPboxWyRZdNGxUN n4fejR1h9n68lKdH0kl5MSZq4QlYVI/18lWWXKVttSF2/wBuaBlnr6fQ24rOiPyY M/Nou38kNGDORt2jj6BVAcJg4CMgwC78onlMV0/gMRCcfcTheoMDjeXqGOvdV5ST gybjrmMQ8LzUyxmlbSI/7Rk1/dugou4apkMKas/h9F6yh9kwLAgks93YTg5CY86T eMu79rFfRYq7JaIv5pMcxSo76ATxZz79x8i2CzXydzICcyzAXCf0fL7f1VFGEv/n WWUcDca1veH3q8YrOpTk3IDWGQwImkdYenNALD+ES7JvQ9tn2vZytk4wPonfY597 Rgttp3DPdc2ouXccl4AIMHkTWRBiYco0S5y2nMY0QpasG4VAWsvPf5aJ3oh6muus PUC7W/LTpbrYEkZBMMYrCp4pBIQWSc39CjERmSIAuL56ENcTb/ubj4o6kCWxSU0Y wOJn42T78tU7gk0JM3Bp++iHREvtdJxLApG6QAqjLgmcpa8A8S0BTsKOhyUavx5j 956Nn1vwY9IyZA== =M1jb -----END PGP SIGNATURE-----
Attachment:
pgpuSjWZosagU.pgp
Description: PGP signature