-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 12 May 2022 20:53:05 -0400 Source: lrzip Binary: lrzip lrzip-dbgsym Architecture: mips64el Version: 0.631+git180528-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Stefano Rivera Description: lrzip - compression program with a very high compression ratio Changes: lrzip (0.631+git180528-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Security updates: Two issues that allow remote attackers to cause a denial of service via a crafted lrz file: - CVE-2018-5786: Resolve a potential infinite loop and application hang in the get_fileinfo function. - CVE-2021-27345: Resolve a null pointer dereference. * CVE-2021-27347: Resolve a use after free. - CVE-2020-25467: Resolve a null pointer dereference. - CVE-2022-26291: Resolve a multiple concurrency use-after-free. A memory corruption issue: - CVE-2022-28044: Resolve a potential heap corruption. Checksums-Sha1: 11c06eb65611234f6471b9854bcbd1dec48ca6ca 800872 lrzip-dbgsym_0.631+git180528-1+deb10u1_mips64el.deb fe1c2da40952de9c55d9fc61e302c174c4d8f97d 5648 lrzip_0.631+git180528-1+deb10u1_mips64el-buildd.buildinfo c3c9d4be2e0fecf715819780bc4ff0475caee1d2 271140 lrzip_0.631+git180528-1+deb10u1_mips64el.deb Checksums-Sha256: 6a6b418b1f2ca69001e9a7e5b4f9fc6550b3e4f751db7d1aed93f7628f52c0cb 800872 lrzip-dbgsym_0.631+git180528-1+deb10u1_mips64el.deb 315dfb23eff4295cfdd710449fae73a2c016c56127ad1d39722f26a64d8ed5cc 5648 lrzip_0.631+git180528-1+deb10u1_mips64el-buildd.buildinfo c612a599b6d4dba6df580b484847c23cc8d03e14afa8be79a834c3049e2faf26 271140 lrzip_0.631+git180528-1+deb10u1_mips64el.deb Files: d2b00a393fe93650e527dae004769dc1 800872 debug optional lrzip-dbgsym_0.631+git180528-1+deb10u1_mips64el.deb 8fa756facedf66795f7f60b508765996 5648 utils optional lrzip_0.631+git180528-1+deb10u1_mips64el-buildd.buildinfo 6931bb113fa853f2359b448a3266aa49 271140 utils optional lrzip_0.631+git180528-1+deb10u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEB/LZjIxKoy4YPfehZlR40KOuoLkFAmKH9OsACgkQZlR40KOu oLn5MA/+OFajRjQTxABHF3uHM5oKrMYFs5OIBH0lrZfwkhS+++MkoA8rzygOpgAu Dp2N+tws1TFrjQ60ol4/SbmXUa3VNpg1+kJOLEwBY3+UxkJ2v+zQ/b2U3Y8sv/TJ miHp9xQT94w56B4xerDkcwjdDaY1dWKFmCGEOvmKGqLJuiI1js5ZQEh9rqPYY6NQ kfgllE99oAPG9MqPbmnOsOTISR90ad+wxJ9KciMRwbVBDE+zKjN82yS5xqORvkox fhVmS7nnzksk0guyXWTcxxGQXCGl/CVDf6YFSzVFMh+gFkiIs7dfjYBncOJSGlTL l7kb2ze17aDS1AD9oDPgtZhWVnxRnGESRgsXs0wn+IDdq/475DnCarfXn+bkmmTq TvUcQ6VOzEEjSkxpelw8wQdjmkXvc2qg6hxv2tINaeJdEUIBN2iCOCJNzgJm4zB4 yKSjtkovms2r47gL4xwVDr7UsGc3OjCZlDXDmWEtKvZT0MUCBwy8MZi/SBbeN5g0 ll4+IcchZUOzXbngWEkl5/Z1U3uuQkNdVeKfI3ZHZIZw0XM98GY55YsjzBHAjRpb 7osMQ31hPYF6xhPUXFWqwC1sRdkYWLDVOlt7rgkHuEypfnd3a9wm3cE563ke1utn FzOVT+XHdI/sgwqB0NDVI4n1u/6jYJn49QCjU1w8Ph64z5HBlLQ= =mqF7 -----END PGP SIGNATURE-----