-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 26 Aug 2021 21:03:02 +0200 Source: gthumb Binary: gthumb gthumb-dbgsym gthumb-dev Architecture: arm64 Version: 3:3.6.2-4+deb10u1 Distribution: buster Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Thorsten Alteholz Description: gthumb - image viewer and browser gthumb-dev - image viewer and browser - development files Closes: 948197 Changes: gthumb (3:3.6.2-4+deb10u1) buster; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2019-20326 (Closes: #948197) A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file. * additional fix in case orientation swaps width and height Checksums-Sha1: ba4a8def199677341d0195fed6bd22f65ed7b000 4558480 gthumb-dbgsym_3.6.2-4+deb10u1_arm64.deb d4118808f576510d053e7414a052f3778f9ee262 611996 gthumb-dev_3.6.2-4+deb10u1_arm64.deb 282ebc8b197cb5dcc8b7daa4862d6b87e45b9338 21356 gthumb_3.6.2-4+deb10u1_arm64-buildd.buildinfo eb74adb200560b781439288f262860213713d04e 850556 gthumb_3.6.2-4+deb10u1_arm64.deb Checksums-Sha256: ac608dd5c5ac26a9ee16b6068c5bb11b3e20fdaf211eacd7ef1f7e4a40c7c239 4558480 gthumb-dbgsym_3.6.2-4+deb10u1_arm64.deb 74a2ce0c1f72f37153c27b1ad89fc4f896af6ea76130e3f5656f3abff24934ad 611996 gthumb-dev_3.6.2-4+deb10u1_arm64.deb adc15f9e3af6fb3276a67badf4bf51c980f354545be974e3e397d28b88b607fa 21356 gthumb_3.6.2-4+deb10u1_arm64-buildd.buildinfo f8d9cd9db47d8cbced5c5319c06e082489388aae8198126293dddd72d9e5b144 850556 gthumb_3.6.2-4+deb10u1_arm64.deb Files: e6d6a0a554ced04c766dcd056f6108b2 4558480 debug optional gthumb-dbgsym_3.6.2-4+deb10u1_arm64.deb df5c14d95263d6a058745b06ad240c35 611996 devel optional gthumb-dev_3.6.2-4+deb10u1_arm64.deb e0cc5868bf1dd38b88e4475478b78b43 21356 gnome optional gthumb_3.6.2-4+deb10u1_arm64-buildd.buildinfo 4ca0b878a28c91a551c9365d22a4393a 850556 gnome optional gthumb_3.6.2-4+deb10u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEdeJNJ1wa+XI5wZnVTG8USxKxETwFAmFPihUACgkQTG8USxKx ETzd2RAAh644f2PgJydMIYYf6OBJVx8CBRwTTnjrbyLtkZqDqzIX3TTDPz+jpjoj mbu8HfFfNVvA+d2HOXC0osg9zGPVMnqzZoaOttk1fdJTd/1Se49ryYMydJT5FhDt VyPAvZTuaCtxArX0Z7XE6Dl6g+G7npJDNtkH3ucA1bJ1/FAsexxineC9q7ATBKd8 yF5Zqt6vOYwMAZHbTXZ5cywXqV1qzW2EehemujayfeFW3xxqa6JPdOZ00jZD0iBJ QCa61BJmDE8QVNpx7UWrZ65uFH9CtfQKljh9BOl67tsO7aS2nZ0M9n/y14CSpYFg fFi3C+MUrMVIxo7GHm+hyXfTa/suUlL4oQXEwc8rUJFQn1mCsu8oJT3ajFEcDymt n+xDpZfCk0NrWZnF/Nz8TYNBr2bxr4o3BHo3y6Ikh2bPe20XIR6O29/EXcSZyojY ex+7PiXgfYDNqMxeYYHXg3wd5JxGECrJD6tHoSf7VKRegeN/5zNHGWbjkjVUuS6U oeOh6eB55zRVN7LoSGfWNS5hxtyD3sWr6kDIDJ2ZC1H4tEWAJ1vN9312k+GyrDCF BfoojgB5Icpr0vfUgEqyL09TO8H2odjnx3QKj8PLs5nW3TD551yjM+wQ0GpvQ8gr SEJGzml7aTR+hxTaZJmPHet91yEn9wxa24+Mi/0dWn3H+fc7yaE= =br2A -----END PGP SIGNATURE-----