-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 06 Aug 2021 11:46:33 +0200 Source: exiv2 Binary: exiv2 exiv2-dbgsym libexiv2-14 libexiv2-14-dbgsym libexiv2-dev Architecture: i386 Version: 0.25-4+deb10u2 Distribution: buster-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Moritz Mühlenhoff Description: exiv2 - EXIF/IPTC/XMP metadata manipulation tool libexiv2-14 - EXIF/IPTC/XMP metadata manipulation library libexiv2-dev - EXIF/IPTC/XMP metadata manipulation library - development files Closes: 950183 986888 987277 991705 991706 Changes: exiv2 (0.25-4+deb10u2) buster-security; urgency=medium . * CVE-2021-31291 (Closes: #991705) The fix for CVE-2021-31291 also required to backport a few patches that fix some (harmless) CVEs alongside: - CVE-2019-20421 (Closes: #950183) - CVE-2021-3482 (Closes: #986888) - CVE-2021-29457 (Closes: #987277) - CVE-2021-29473 (Closes: #991705) * CVE-2021-31292 (Closes: #991706) Checksums-Sha1: ef1f61b815cdd237095a4ed6ce5a2a5f74b43363 729588 exiv2-dbgsym_0.25-4+deb10u2_i386.deb 1792e2b3d4ad94b576e83d246e03fba7eb5f1db5 7316 exiv2_0.25-4+deb10u2_i386.buildinfo 8a164ecad9cb4da3a8a3f6e673345aecec303697 113392 exiv2_0.25-4+deb10u2_i386.deb b2a33e4d0f0a9a00ac1b0f49ac3e4a43328c4ad7 7796844 libexiv2-14-dbgsym_0.25-4+deb10u2_i386.deb e5eea36dd651bc023c4413c77ef343afc40cec22 724552 libexiv2-14_0.25-4+deb10u2_i386.deb eb4f318a347aff0a70b2e34e6c05dc546c7a558f 1613900 libexiv2-dev_0.25-4+deb10u2_i386.deb Checksums-Sha256: f87ef8264b0cb828789ae5078add312a2c1eb592170cce5edcee6599b44fe468 729588 exiv2-dbgsym_0.25-4+deb10u2_i386.deb 79021f937944919a5550e83bd5fa678d429f69cd5a84e4d1896d67a4d2531a0d 7316 exiv2_0.25-4+deb10u2_i386.buildinfo 928226c39d737b2f64f57f4fc7057b19559c6a2ddc67da57911da6bf5cc79225 113392 exiv2_0.25-4+deb10u2_i386.deb b9191a3b4449899971c0bba8a0a00916c3e07da0424a4427599dea63d53819d6 7796844 libexiv2-14-dbgsym_0.25-4+deb10u2_i386.deb 0a2e66d81a6b415c562df88c10026b7e6b433c2070a301491869308c3cde3c47 724552 libexiv2-14_0.25-4+deb10u2_i386.deb 05963531a1696cfa014500f106ec1165be0547d91474747c49582f859d4eed9d 1613900 libexiv2-dev_0.25-4+deb10u2_i386.deb Files: ef14aed1ca006c1a0a1ac42d1c832fdd 729588 debug optional exiv2-dbgsym_0.25-4+deb10u2_i386.deb 409913779c71bdbc425a64057a5187cf 7316 graphics optional exiv2_0.25-4+deb10u2_i386.buildinfo 424784591dee631021c1295047917738 113392 graphics optional exiv2_0.25-4+deb10u2_i386.deb 070ac5e1b04d89327438c1efd5a06db4 7796844 debug optional libexiv2-14-dbgsym_0.25-4+deb10u2_i386.deb ebd3303c8714200481b451baf993e3b2 724552 libs optional libexiv2-14_0.25-4+deb10u2_i386.deb 2dab824c784e3ffd146f854286ba5a23 1613900 libdevel optional libexiv2-dev_0.25-4+deb10u2_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEeShLnnjT5e2dm1q4H4Xht4aLclgFAmENFZMACgkQH4Xht4aL clhFpRAAiFUfmFY1z2QjTgcCyEPg2m35kAa53HqFBXM3lhxAK4hJ25r/E/SBT0KM +gvOYbgImoyFJ9GeYTPJlJgz9dPYkqfom8GuBJSRi8AuFypnh9luvu6cJrPFP4Qh 4H0lkFefR/BValra+0UPiJhLIR7a/OES6dLKLKONQYwUvxZeFV3krnqNVI/kFQxc r1qM/xs/DaAj2WgarSsuZXsdykXr+sMrR4eCMW2t4ZeJ7ZPy77XcPisyhWqbQ8QN qchvVAKeI6fO2MduNDREz448PN1MPORH1i6GlHEaqTgQ4elfff04li6IniaLRY/9 ASHO0HntiSSbQkklXy+1+bg/9uPI62VblcUWyv9hDtn5Sapo0b+HqqrHPSWZ3qs+ cCoVsFKeW4v/A/xJlK4/obhJh60VSIpEpY6fMKF2bCuSUvm5QK1jfNy/Mc1PbiIJ hBAMnPR1jZT8zbK8FxVfxsdljcQtRO/lWhtYqFgPmwSoItWzZ2k8IZTBcFkBdNbh NG3D+YxH1rWBxCc/IalfK7bnGqPjyA6ry+6DPbXO5Bjpcpkt8cpJuTu5Q/rNMjrU 7o5kiIrQm8aoYbGewt2IyuHl7FK/UFk9LLz7Ey1Q7G0FzfY4O2YonOdMuoUPrWNV tsaKnK5bDVOarqWxTGWHSB860fb1Ho9eDyGOMbvFIuxV3Krz+ww= =KPGB -----END PGP SIGNATURE-----