-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Jul 2021 19:03:02 +0200 Source: aspell Binary: aspell aspell-dbgsym libaspell-dev libaspell15 libaspell15-dbgsym libpspell-dev Architecture: armel Version: 0.60.7~20110707-6+deb10u1 Distribution: buster-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-04) Changed-By: Thorsten Alteholz Description: aspell - GNU Aspell spell-checker libaspell-dev - Development files for applications with GNU Aspell support libaspell15 - GNU Aspell spell-checker runtime library libpspell-dev - Development files for applications with pspell support Closes: 991307 Changes: aspell (0.60.7~20110707-6+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2019-17544 It was discovered that Aspell incorrectly handled certain inputs which leads to a stack-based buffer over-read. An attacker could potentially access sensitive information. . [ Agustin Martin Domingo ] * CVE-2019-25051 (Closes: #991307) objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow Checksums-Sha1: 614b50a120d8652094ff27a9da2ac56e0ef9fd86 537488 aspell-dbgsym_0.60.7~20110707-6+deb10u1_armel.deb 5d8f2484eba0c06e2e906ffc0e6d13bea7916e95 7407 aspell_0.60.7~20110707-6+deb10u1_armel-buildd.buildinfo cc76dc15579f8e073cd4c89e357e605f88141796 218612 aspell_0.60.7~20110707-6+deb10u1_armel.deb e11149e28f1da84747eb56bb13a8a32796f18039 32856 libaspell-dev_0.60.7~20110707-6+deb10u1_armel.deb cd314e13c85e58e54c3ce52f74ca9144df0fcf6b 2690464 libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_armel.deb ac25d003bc338bdc0910a6852c916a1deab92343 274560 libaspell15_0.60.7~20110707-6+deb10u1_armel.deb d54046be90e2d5b0831f6d98551cd19a0d32df67 29948 libpspell-dev_0.60.7~20110707-6+deb10u1_armel.deb Checksums-Sha256: 61ee434b3e65547ee55b97153f5fb0a2c3e98249a58f9f86a23047a690ff3d55 537488 aspell-dbgsym_0.60.7~20110707-6+deb10u1_armel.deb d56f3429bc3ca6a65ec301552ade761a33645e3e41b8bbd732f243f03f5a1907 7407 aspell_0.60.7~20110707-6+deb10u1_armel-buildd.buildinfo f783ff6a0225afab9c3c0664264111842ba98c42166fff06ef2d41558fad9c18 218612 aspell_0.60.7~20110707-6+deb10u1_armel.deb aef870959f5fe8eaf64cd671bf3bfd1710fac3c7881edd299f91d68d6686d22b 32856 libaspell-dev_0.60.7~20110707-6+deb10u1_armel.deb 9e4f7de9fe5be43c2cc4fcbd02efc5d4201e3e76de48d9c14bad36c4fbda7c2b 2690464 libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_armel.deb fdc9a18c7f8bd0731fe69fc7d92a72f843012e01f0a08d89e9c668a7b5cfe238 274560 libaspell15_0.60.7~20110707-6+deb10u1_armel.deb a4557f7acb7caa01abdd13b7afa30fed66ab5a3291f03cd106de63f4a2fd6b3a 29948 libpspell-dev_0.60.7~20110707-6+deb10u1_armel.deb Files: a2bee36f858d61c51b0717f8e3bf5082 537488 debug optional aspell-dbgsym_0.60.7~20110707-6+deb10u1_armel.deb 95c2ae324eae9761bd6fa68324250904 7407 text optional aspell_0.60.7~20110707-6+deb10u1_armel-buildd.buildinfo 41e46f6d9c56c9a6dcbad72fb6270c94 218612 text optional aspell_0.60.7~20110707-6+deb10u1_armel.deb 86f195e6653d82d2731fc36d2b726a2a 32856 libdevel optional libaspell-dev_0.60.7~20110707-6+deb10u1_armel.deb a318c58b6952e507600303b41923f9e4 2690464 debug optional libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_armel.deb 2cf875c99b53e07aec9b89d7aeeb555d 274560 libs optional libaspell15_0.60.7~20110707-6+deb10u1_armel.deb 23c2db3cba46c4188c6803979120fb54 29948 libdevel optional libpspell-dev_0.60.7~20110707-6+deb10u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnkOoRyjJ0+t2tN7OjOf+cynECFcFAmEEi7IACgkQjOf+cynE CFdyzQ/9EaQqz0AEjzkbK6h6ydpQ0uaClWAscQcQkvYTL93o3m0Qe1HXDKv80cWx +X9y2U7x+rWn1dDV1Zo1F4JcI6pumJlRhDhmbr58Gg7c9yE9hTB4fSaHqXB7mDZ0 YKyiuvz7Hkc2unEr5hWGm0fTcge8QrMAhFth0srNzu6G/F8CTffHNXiyHhe9ua2K acagHBq3OwK6vxnGBUXuWhE2d5d3P4/V9N1He2AiVoWBZgzNdYnk111KpJxt0YWY lyLWzmHhCeP2BIp8qM5Nez5tF6dwI1Klz3qnVdDwjT6RyAmwTTfpZ53iI8KmfpWT iVHUa+5xK1RBiws0pu7/hlwmTin9mOyfIl8Z4ptP1qoJTbH25LbuNtnZnWgBHTk+ PDraKwuTGPuuUBjs8cYgA8Tz6o7FmvTesSpJuzyGdY0Nqoki6b7TcZTp+mrVxCNK HgSwWaiMTPoBpzeNobu5JfOBAVbXxvlMdIlpXEa4C2fCwzsorCfNhv9FXXy0xycw JHMw5NN6S1GioxS7yTLBZnI7YBaQ7QhR246JCJ24yvtlc+Xvkg+2RcM1TWzUo3Ek t1MtJPbOKSSB0HKZjO1JL8kT5baedPBqi8p4V7ldiKEoItYks9oomUe+4k092bzA uQasd+HwXfovXdfiPzhChw0Q9KnZIL4IsW+YNc14BhevFTLD+Uo= =PXHy -----END PGP SIGNATURE-----