-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 26 Aug 2021 21:03:02 +0200 Source: gthumb Binary: gthumb gthumb-dbgsym gthumb-dev Architecture: armel Version: 3:3.6.2-4+deb10u1 Distribution: buster Urgency: medium Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Thorsten Alteholz Description: gthumb - image viewer and browser gthumb-dev - image viewer and browser - development files Closes: 948197 Changes: gthumb (3:3.6.2-4+deb10u1) buster; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2019-20326 (Closes: #948197) A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file. * additional fix in case orientation swaps width and height Checksums-Sha1: 9332df87667ce910b4b2d3e67ca7a044f92f60f9 4438596 gthumb-dbgsym_3.6.2-4+deb10u1_armel.deb 27f373ef1b862b3e835c7adf5947ef27f13477dc 577412 gthumb-dev_3.6.2-4+deb10u1_armel.deb f61a48c276978156bbd406d93976e946c847c3d2 21315 gthumb_3.6.2-4+deb10u1_armel-buildd.buildinfo 175ac7150374f7ede9cc0c0c82be35b1318c732f 766748 gthumb_3.6.2-4+deb10u1_armel.deb Checksums-Sha256: 085d43445b71755c5e1d55f9e23ca2f56f1df49285ac77906417e54da9ddf78b 4438596 gthumb-dbgsym_3.6.2-4+deb10u1_armel.deb ff3754b7a7d018fd91fb48a02b4b015ffc529535765f199490fefafd75f50438 577412 gthumb-dev_3.6.2-4+deb10u1_armel.deb aa242fe4abb3a3d0206af8efdbe38edcdb1434dd280dc9569df93e9a396caf88 21315 gthumb_3.6.2-4+deb10u1_armel-buildd.buildinfo 5608327527aea738d172feb3b109aa8d217ccae7b6eb0341c59a9bc0849711dd 766748 gthumb_3.6.2-4+deb10u1_armel.deb Files: 11e1deaf387d8971f907a1d09cb432c7 4438596 debug optional gthumb-dbgsym_3.6.2-4+deb10u1_armel.deb 9308d018930a73cf643daaf4dfab3b57 577412 devel optional gthumb-dev_3.6.2-4+deb10u1_armel.deb 96772b7ab4a839faddef5f021241ad5d 21315 gnome optional gthumb_3.6.2-4+deb10u1_armel-buildd.buildinfo 95a04c577e3895305fe9e68e100731b5 766748 gnome optional gthumb_3.6.2-4+deb10u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPIcQGfwFnp2nqr8+Jnu2SCkm/soFAmFPjGsACgkQJnu2SCkm /spUlhAAxFHHA6vViYBE+BEAGRWurBYx6d/+mfV/B6T2gKaGapiiuCFBIEcIQjFp eVswlGceDK30ndglueZ1qdRxCL197rsaQaZ+IygoQR7or0B4dwh0DsMJLQLqgOTb RAIJCAOcZ9AUdBKM1YQ4eyGkSMK4wzHcBkYjdgEvQefv1hQod3Adzp5q4xl57gev cLmJZ1dcrsdGeF2U9fP0NerO6c8MArIrQubfJAjrNYVIQAT+LHq6+iy8aXxjIYMy rt4jOxYkQXyVL5D6Ewh7UK7Gahhb1JlrA5RHCrbBc/2d/GthsiDPGn9npM1NXbrP rJ1ScCgPiSuskAy8j9b/tXG89kgLAbbr7xsoyon9jPNBsLFLNSYH4gbziPbYC6jM 3pahi0nUKeosOCpPrCkfRLFc15t7Wli0R15hLjk5iiSoss2tA6zPH16WL3dyq7kw rZuhyNokT32UM/ZzSlyFz7WwuGknu7Uh7uYcvsv/JBk0wag1iM81NUhCNjoKXMIS l0zc2sYTxXrkc5cErsYyx9uyjL//PnDEm42lFD/0pt5jw3x00nlTYXm/tMsj2FwK XbO+N1z2nhcvlhfxuSXoFOTlyA1bdf3ZhlpNBNRiuBl5tNd1AZf0QWzkhgSWCl4b TXQ+k3abwcIT4Sgf+bRQrLANz8rUQsJ4Ii34BntoIwLGuXe8tqw= =dzpA -----END PGP SIGNATURE-----