-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Jul 2021 19:03:02 +0200 Source: aspell Binary: aspell aspell-dbgsym libaspell-dev libaspell15 libaspell15-dbgsym libpspell-dev Architecture: ppc64el Version: 0.60.7~20110707-6+deb10u1 Distribution: buster-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Thorsten Alteholz Description: aspell - GNU Aspell spell-checker libaspell-dev - Development files for applications with GNU Aspell support libaspell15 - GNU Aspell spell-checker runtime library libpspell-dev - Development files for applications with pspell support Closes: 991307 Changes: aspell (0.60.7~20110707-6+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2019-17544 It was discovered that Aspell incorrectly handled certain inputs which leads to a stack-based buffer over-read. An attacker could potentially access sensitive information. . [ Agustin Martin Domingo ] * CVE-2019-25051 (Closes: #991307) objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow Checksums-Sha1: d29c1eab208062b7b1680073e95cdc2a5b290aff 549772 aspell-dbgsym_0.60.7~20110707-6+deb10u1_ppc64el.deb 9d66ffc8e3445672e59cb4da978fe1eb10f26815 7546 aspell_0.60.7~20110707-6+deb10u1_ppc64el-buildd.buildinfo d1390a090576a30ddbbb7a0f34e25a678249fe9f 233348 aspell_0.60.7~20110707-6+deb10u1_ppc64el.deb bf3006555af373d50e658c5cf89ab7479731c3f6 32868 libaspell-dev_0.60.7~20110707-6+deb10u1_ppc64el.deb 39823a5aa7a7fcd9e5a1ea8b199d6b70dd73f4f2 2786340 libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_ppc64el.deb 6a3b3f6e1f71151e57322b558e4dd9964898a4c7 342756 libaspell15_0.60.7~20110707-6+deb10u1_ppc64el.deb f5c8dfff37a078afe46da4d547b6f177836399b6 29952 libpspell-dev_0.60.7~20110707-6+deb10u1_ppc64el.deb Checksums-Sha256: c2c9bad5dcddb5a74363ada76385c1d351e4ea48c99ea1b1cbae45b09fac9836 549772 aspell-dbgsym_0.60.7~20110707-6+deb10u1_ppc64el.deb 1483a8a11da83a1c91bb9a9868e2bda641c25cc2435e40711e9ba0f5f041a7f4 7546 aspell_0.60.7~20110707-6+deb10u1_ppc64el-buildd.buildinfo 397d34e0d284a266c9778e57215f321a8a3a1f5c2c5ca9bd1dd39b90de0ec97c 233348 aspell_0.60.7~20110707-6+deb10u1_ppc64el.deb 83a93c3958ba9540e9a5a71935e2a24ee3546b9f44ae9a00e25b27b57fb608ee 32868 libaspell-dev_0.60.7~20110707-6+deb10u1_ppc64el.deb b0c7adafb7fe947aafef1959a5d42ff19bdf94a841285a761a52a5c07e7a233c 2786340 libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_ppc64el.deb 78283457ee8e04fa38e52e210145396eb0ec528080389935ceb6d0fdfb812c3c 342756 libaspell15_0.60.7~20110707-6+deb10u1_ppc64el.deb 61d1038a5355919da2fee417f3a6470c0ac5bec04ffd44caf79d2f066e2d4faf 29952 libpspell-dev_0.60.7~20110707-6+deb10u1_ppc64el.deb Files: 7272a1739982c33d92bb2a799f4070e8 549772 debug optional aspell-dbgsym_0.60.7~20110707-6+deb10u1_ppc64el.deb 18622ed881fb2e90b258af6d1598ba4f 7546 text optional aspell_0.60.7~20110707-6+deb10u1_ppc64el-buildd.buildinfo 647fda233af99cbcecd18bd55d027d39 233348 text optional aspell_0.60.7~20110707-6+deb10u1_ppc64el.deb 0acb231ae66dc64d47c0bbcd36ef1905 32868 libdevel optional libaspell-dev_0.60.7~20110707-6+deb10u1_ppc64el.deb 8518629b09add5fe8a62e664a878a84a 2786340 debug optional libaspell15-dbgsym_0.60.7~20110707-6+deb10u1_ppc64el.deb 8aedddc864ba0a46c2aa8278aa3cc82a 342756 libs optional libaspell15_0.60.7~20110707-6+deb10u1_ppc64el.deb 97e778edf2da5a9033de16a8dcd33d6e 29952 libdevel optional libpspell-dev_0.60.7~20110707-6+deb10u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzxcBZLbWYROS8SGLQ0vh8H8HxvwFAmEEissACgkQQ0vh8H8H xvx+wxAAji1I1dWyqInn1P/72+h0XrXrOzjRFqP8HV40NbxQPqqOIc1NbegW5ulB GM9NOATCu2tPkL7S42jL5YAq2HJTr7wNFjJQRGkHP8kId1TQY9QJq8BdDb4fCm/b PAGhsRMOPK4aPVyi8SxZRKiE0tUAGCVYpTTyGs89xuHFdG4hS9DUNDSj+vHkmxHn Xvh5AlyR8IdHkgfHNa0TWfeDNefj4vddSIShLhmIgVevofpC4x0xHsL/vLocUBaM bc65Kr+9MxNdiZp4zgKmzAYYbOmXjUloa1e2ewPN8P+4SuST4tbAphEOmauK0p3K wSvtZjp/HKlSDSn555BH5mFbeaSmlGjtnC/1xnRw9hyhtwvJuZrcelBpGPSfn99f Ps+bdlaPMshCw/XOfeYJGCzCGDH1BdOOKZ+tsjZUFFv8dJUa/SawsAEU56jIzalK Ch6f8r9uCUM5fDkEhxP6eZxeKXV8fp13Aeb+qy/jbX+CTmPu83xcDcjeD+HtNv6a 9rSeituiWyz02TtO1dBWJRs3mV8jPLchvdUbB4LQfTnOq4DeWUedbSTHnVAB5CNc CCdfS2VEJPXfjQjyUztMDFA0M9LHmC/xyFa5XZFqa4TBUyR8nw3bCLNUG8+M1GAu IuG5HZoP9BOWweLmA0SpMl8uTMvuc4PU5TWyyIx+xeo6Q41oIgU= =EF9I -----END PGP SIGNATURE-----