-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Jul 2021 19:03:02 +0200 Source: aspell Binary: aspell aspell-dbgsym libaspell-dev libaspell15 libaspell15-dbgsym libpspell-dev Architecture: mips Version: 0.60.7~20110707-6+deb10u1 Distribution: buster-security Urgency: high Maintainer: mips Build Daemon (mips-manda-01) Changed-By: Thorsten Alteholz Description: aspell - GNU Aspell spell-checker libaspell-dev - Development files for applications with GNU Aspell support libaspell15 - GNU Aspell spell-checker runtime library libpspell-dev - Development files for applications with pspell support Closes: 991307 Changes: aspell (0.60.7~20110707-6+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2019-17544 It was discovered that Aspell incorrectly handled certain inputs which leads to a stack-based buffer over-read. An attacker could potentially access sensitive information. . [ Agustin Martin Domingo ] * CVE-2019-25051 (Closes: #991307) objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow Checksums-Sha1: fbf146f8ee5f4e6b125ace4f575424c943e0f2d3 562468 aspell-dbgsym_0.60.7~20110707-6+deb10u1_mips.deb 8d82243b9dc62794102e86f5a5c1394ddd9e746b 7337 aspell_0.60.7~20110707-6+deb10u1_mips-buildd.buildinfo de107df84af79add169b8bddd988444d3918adfd 221240 aspell_0.60.7~20110707-6+deb10u1_mips.deb cac7f74ea39ecd772367851c0066ae178d5ed843 32864 libaspell-dev_0.60.7~20110707-6+deb10u1_mips.deb 0a83fae05003e9a51aaf4e8844389f72bb67e4b8 2807252 libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_mips.deb 26d960d1bbbba5f1572abd8fd86050224dea5b89 272180 libaspell15_0.60.7~20110707-6+deb10u1_mips.deb 3df553210ec01652a2c44bfcfac779c82d691177 29936 libpspell-dev_0.60.7~20110707-6+deb10u1_mips.deb Checksums-Sha256: 7c7941f5271aa313b5e761f04e52eba7767c17c3e0e887fec7f155dbb33635f1 562468 aspell-dbgsym_0.60.7~20110707-6+deb10u1_mips.deb df215b88071710a78d95d88da0ca3ac22ef2998940110f31b95461da30f4ed75 7337 aspell_0.60.7~20110707-6+deb10u1_mips-buildd.buildinfo 6aa1b15614293fe47d3fb5daef83944100921f047885c5ea7d90f499ce1b08ee 221240 aspell_0.60.7~20110707-6+deb10u1_mips.deb a36f287e2395f06df60b7d481127adc71da7baa9ae015e2d905a091930e4bc09 32864 libaspell-dev_0.60.7~20110707-6+deb10u1_mips.deb 05939396496e75c71492df3a06a7b8dbf4a6f5325199c3ff008e3a65ef779e42 2807252 libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_mips.deb 7f65d242f88779b0baa9e6d9d407423e858474e4b5fc26a849dc59dcb4760a51 272180 libaspell15_0.60.7~20110707-6+deb10u1_mips.deb 7e4768e4ad46c7624c9d8df082872b6783fa64d86786691f5322b45dac889cad 29936 libpspell-dev_0.60.7~20110707-6+deb10u1_mips.deb Files: 26c8565c39b8d4a1007ef49822d344a2 562468 debug optional aspell-dbgsym_0.60.7~20110707-6+deb10u1_mips.deb 5afe81916eee4835c3b9046103422325 7337 text optional aspell_0.60.7~20110707-6+deb10u1_mips-buildd.buildinfo 244ec07c0f8499a4d11551a15764db53 221240 text optional aspell_0.60.7~20110707-6+deb10u1_mips.deb 8365d0cd171a1f395a653adcf040ac4a 32864 libdevel optional libaspell-dev_0.60.7~20110707-6+deb10u1_mips.deb 4db81d7172780624f4f79dc47728a1f7 2807252 debug optional libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_mips.deb d3e05210e2e403138c2f638a74e192d6 272180 libs optional libaspell15_0.60.7~20110707-6+deb10u1_mips.deb a946d92bd6df751cb6075ee99edd046d 29936 libdevel optional libpspell-dev_0.60.7~20110707-6+deb10u1_mips.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEhnMg2w1ioN6Y4CfNHxQ53MmvhPIFAmEEjLAACgkQHxQ53Mmv hPK/wBAAtGFm155l1gf/dezurQs7DmKHUm6lXX4jIvFPorHnyGEPMg03Ypk/LOk5 pO9ps+0YH7zV9OkPmymYB+XctllF1oz+o4PBeYoKxl+smriEUDqVv/najBK6EvgB nX+5HSN7BjBGlG6opUSKfPTlR2XMdLL6lyt/3As5vO4ywaH8RsBdQlZzgVGrR2eQ DoYI+KC3/uSEKvGrqIKLAgpb0h3crKBAw/kHYTHRAkaSqQ21hvwgwjWV33dZ0A/p QXGf6lLGJICh96rV7hrY00JR5Yt9TYwcNAU+ntm7DACHp9SecY/Ob/AyrdH38h+A aYY82FoyR7FVs4xaXTR3POFCdqAx7EfnSopvVVE0lvXNzO+TXQtsxYQjvbAJu3A4 cAHeSijH+G1f/gJGDZiGRVjk3c6mwUnmwshsbxSLEVaMm4uFEmPCHbkMffEMaxVq XKaPGZRu3b06bkGEK3MZifm5iQitRiJK+6GDDD3ChzQqVoaYWzhZM191BMsqfNCw y3r6z5qrUA7DvNhiY/NqrwFrQCcSB/Ca+/r8AHWDZZKt9T8ed60+yDnlCFAbS0Cc PbJ85tYC088+VrmGV1HkPG8ztbBSFlyOoRNgcaegwlfM77LQ90G7IFXPVDhI+NbC ESsb7dQp6/tOJf0ib3eCSn5TLslvrO2VDmDN/aYdAAWQ/qTi2r4= =6cBO -----END PGP SIGNATURE-----