-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 26 Aug 2021 21:03:02 +0200 Source: gthumb Binary: gthumb gthumb-dbgsym gthumb-dev Architecture: s390x Version: 3:3.6.2-4+deb10u1 Distribution: buster Urgency: medium Maintainer: s390x Build Daemon (zani) Changed-By: Thorsten Alteholz Description: gthumb - image viewer and browser gthumb-dev - image viewer and browser - development files Closes: 948197 Changes: gthumb (3:3.6.2-4+deb10u1) buster; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2019-20326 (Closes: #948197) A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file. * additional fix in case orientation swaps width and height Checksums-Sha1: a9a5fea14e49f0b69312bdb644a194f08b2a80b8 4573360 gthumb-dbgsym_3.6.2-4+deb10u1_s390x.deb dcbf2443575c76b1a9d70f8a59246a4054d6c1f6 586980 gthumb-dev_3.6.2-4+deb10u1_s390x.deb 52a85a85380e85c3acf87eac55ad4ff70c05ebe0 21231 gthumb_3.6.2-4+deb10u1_s390x-buildd.buildinfo 3131a1c5e911a8a51ad9942c68962b61e9e57eaf 853048 gthumb_3.6.2-4+deb10u1_s390x.deb Checksums-Sha256: 2b6bae6b71230dd3b0bc130c3a3aad63b463f94dfe870b500932329ed6440b70 4573360 gthumb-dbgsym_3.6.2-4+deb10u1_s390x.deb d6d6164a9a515bdd2fd7a53b5a33ce211be10694af4e0e2ef14069bd2095fca9 586980 gthumb-dev_3.6.2-4+deb10u1_s390x.deb 9659e6e5f6a31790ffc8252a4f6252167bb1c948ac41832a372d94d28af218f5 21231 gthumb_3.6.2-4+deb10u1_s390x-buildd.buildinfo b80b1d64b15abe79b08de7be1941669f442baf6788bfb59193537084bd0643e1 853048 gthumb_3.6.2-4+deb10u1_s390x.deb Files: f2886fb35e461318ec33e860abdb4f18 4573360 debug optional gthumb-dbgsym_3.6.2-4+deb10u1_s390x.deb 17e5ee9895b9695e1f4bc052a75a79a7 586980 devel optional gthumb-dev_3.6.2-4+deb10u1_s390x.deb 5c03fdd4449746480eb28c6cdb0c1f4b 21231 gnome optional gthumb_3.6.2-4+deb10u1_s390x-buildd.buildinfo cf18310f1d5041427dc566f4d0f662ab 853048 gnome optional gthumb_3.6.2-4+deb10u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmWIkkgUuS9gv4cQs2fsV5+cTvxoFAmFPs2YACgkQ2fsV5+cT vxosVxAAk6+e/H3lkdRVsTksAwnnty1zmJrCkQsLoAXib8X0rA7plQNY9egd0tGp mdi/nrNNRV8npH0n4Vf3MnKw4VEpOmvk/mh4gsE5C21aFAXfLw1N8Iu2ot1v/0Vg NaA69ho7UVBvl9kmFDrKCXWKVpujHU1Zgi0Ps+Drop+rv0YvieQRacRiV8I+C14d G/tb0wqgzhNe8i0m5eb0ABAJzoZeuL2wRizvWqpHpwDD+QxSU5wKq8Fc6D+9Eqdx GF6gKXhjCpxIdcfc4ORfFMScG4kGMGQIHy1lf32lmlkLEJLn+KLAgU6R0unYZTRk T886GuSDkWGZOSA4KlO4uAFXGy7KJYnQOw8SA8onbblI+XBSqogifhiVLCxWKtMs abPwwuPIbjkmfptl/MMHJP+UuFZpQX1EbHcdKdBXrmFhoy81dlByRYhgib2AqFC4 Ws/emDLU9fKEOumjW/H9xuPMWEMOeTX+cwZ8qbsv1Z6C/aBXtcJxfwuo/S5N8WNB hqNNDydV1SbKCbdEt+GkWQcfIemhvUWznPnm0ZaMAuBq2HlLGKfe5GAyBB52NAZS Q76eO+aT6qZ1kRAFIR1/L5awjydkEjNnOU54M+f6a+MgO42T4+suBlO6VryD33XV QmQwmE3MI9eRxMuvpi7li2lBcRB9ghDqADZtPUeRW6AJIgk6qcU= =VQ/V -----END PGP SIGNATURE-----