-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 12 May 2022 20:53:05 -0400 Source: lrzip Binary: lrzip lrzip-dbgsym Architecture: mipsel Version: 0.631+git180528-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Stefano Rivera Description: lrzip - compression program with a very high compression ratio Changes: lrzip (0.631+git180528-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Security updates: Two issues that allow remote attackers to cause a denial of service via a crafted lrz file: - CVE-2018-5786: Resolve a potential infinite loop and application hang in the get_fileinfo function. - CVE-2021-27345: Resolve a null pointer dereference. * CVE-2021-27347: Resolve a use after free. - CVE-2020-25467: Resolve a null pointer dereference. - CVE-2022-26291: Resolve a multiple concurrency use-after-free. A memory corruption issue: - CVE-2022-28044: Resolve a potential heap corruption. Checksums-Sha1: 5a0227bc40f7092e162f45ee13bc70e3e67f8bef 762692 lrzip-dbgsym_0.631+git180528-1+deb10u1_mipsel.deb 3d40b5f2cac28b444527a3654a5fc59e9a3c5230 5625 lrzip_0.631+git180528-1+deb10u1_mipsel-buildd.buildinfo 6793658d7611ac2acdd9dc3311829cf0b5cb9635 279912 lrzip_0.631+git180528-1+deb10u1_mipsel.deb Checksums-Sha256: 10f7f2770cebe3e1345d74a55b813708bc9e0f756791056106f8d9e78c368660 762692 lrzip-dbgsym_0.631+git180528-1+deb10u1_mipsel.deb 5ddd997f4ae764b08d8ecb6d122050e0fb006fbf4fecc636eee13e83f794894d 5625 lrzip_0.631+git180528-1+deb10u1_mipsel-buildd.buildinfo a6d2cb09988e2874ee5e7621c4ce16b37bc064d835bbac719cbac98399dbaa73 279912 lrzip_0.631+git180528-1+deb10u1_mipsel.deb Files: bafc21a208f4f80cd48d06a0e88053b2 762692 debug optional lrzip-dbgsym_0.631+git180528-1+deb10u1_mipsel.deb ee5efcb6225c38465ac6ab88bb0ab946 5625 utils optional lrzip_0.631+git180528-1+deb10u1_mipsel-buildd.buildinfo 5b9e59ec64215ff500393acb90b2427b 279912 utils optional lrzip_0.631+git180528-1+deb10u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEB/LZjIxKoy4YPfehZlR40KOuoLkFAmKH9GkACgkQZlR40KOu oLmoUQ/+MDvxXE626qdBj4VsEQJPThsnTq4uOmW3D55Zusbq+zrl0OMdBHaD+gbi mnWUHcDAF2jKLM6V97WXthvHx0DT/NTpAbX8EhGHisFbe7lDu0W+AKIClo0z+bBl 6VPfAzDhFb+b/0ySG7TAosTZBUwKSBTGi4Ea2FD1hK1ZxtaH1oIE1EYr7sVzHVeX TVQm36O1wPo/pxu0q2lxwwNKLqK7ubNZEOhUlbCOaghPOQe1BUJTE7RSZy+4HmDR g6HZ0fdQSdjffNHcWloTeHbxnuTR6fggMQ/ksyaXEO9IWGQyCfkjo1phPhi3f22k W3d9YwS69fu9JHcNghoGEfacPFmYbj9LcMxq3UPn8vOvn1BLDDMLS93wHhn9xR1K 5y+jRD44nhvp0rtcc/vcIwd0jZP8nrzOjCWa0S6/LwNCk75ytaugTP57odH+HtpA LvoN1ElpFPkdq39NjJ+cMuluHbgvCKeuNtrL/Jb0dJi0aDMlXGgUhvNvFTF5IPdY GmS1iheG5IJpt581xBliACPTMW0c/J9X9huOqA8f7HnnSpEjOantCr3emgTkNSZW xBrfi+MfMrkM/Xf06+N8HsWjT6hbKwX2HNcJbtzEB5xS5iGyslNw6XalYU7ebygW 408waLF3Wd1XqN33mTkh+FaS2RHYOGFithKDQ3XUkxRwfJ+i8Eo= =NEoA -----END PGP SIGNATURE-----