-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 14 Jan 2012 21:55:47 +0100 Source: t1lib Binary: libt1-5 libt1-dev t1lib-bin libt1-doc libt1-5-dbg Architecture: mips Version: 5.1.2-3+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: Debian Build Daemon Changed-By: Yves-Alexis Perez Description: libt1-5 - Type 1 font rasterizer library - runtime libt1-5-dbg - Type 1 font rasterizer library - debugging runtime libt1-dev - Type 1 font rasterizer library - development libt1-doc - Type 1 font rasterizer library - developers documentation t1lib-bin - Type 1 font rasterizer library - user binaries Closes: 652996 Changes: t1lib (5.1.2-3+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * debian/patches: - CVE-2010-2642 added, fix heap-based buffer overflow first found in evince but applicable to the embedded afmparse library found in t1lib too. Fixes CVE-2011-0433 too on the same patch. - CVE-2011-0764 added, fix arbitrary code execution by only using ppoints when it is a valid pointer. closes: #652996 This fixes CVE-2011-0764, CVE-2011-1552, CVE-2011-1553 and CVE-2011-1554 * format-string added, fix a format string error IfTrace0 macro and another in T1_SubfsetFont(). Checksums-Sha1: 1a97f0a681da892dbf4011f73d826f74a6c3bd8d 163502 libt1-5_5.1.2-3+squeeze1_mips.deb 19cea1dbebdee57ced4bf05bb133abc9782b8822 218842 libt1-dev_5.1.2-3+squeeze1_mips.deb cf314ab088488c7ec6061375d8bc9d09283f80c2 55978 t1lib-bin_5.1.2-3+squeeze1_mips.deb 5ecb9565161684fd773f30e2ae98f3cb8a8e5011 222188 libt1-5-dbg_5.1.2-3+squeeze1_mips.deb Checksums-Sha256: 795c9fe52f3d42e22a7e6f800a5adece5072eed962cddf96813f4329ae255fcb 163502 libt1-5_5.1.2-3+squeeze1_mips.deb f4b66655e07d9a4bbbe3a10a03ffc036814be8321b8a8bb0ae97bcb055e5abdc 218842 libt1-dev_5.1.2-3+squeeze1_mips.deb 8f98babf937f25816988ba5259ff6504e50d451b25d124b16514ee4e3141fc7e 55978 t1lib-bin_5.1.2-3+squeeze1_mips.deb 1198e52e5a207ecf455168ced6fa11d091e6c55bd96ec3a54c45f761999bdd37 222188 libt1-5-dbg_5.1.2-3+squeeze1_mips.deb Files: a1daffaabbd0849419c9c80d87ca64f2 163502 libs optional libt1-5_5.1.2-3+squeeze1_mips.deb 7d87c8a367ccec89b9254ef184427e08 218842 libdevel optional libt1-dev_5.1.2-3+squeeze1_mips.deb 54051e39d04156a0b349cda15c5727b8 55978 misc optional t1lib-bin_5.1.2-3+squeeze1_mips.deb 88c85c063f685bff398c8deac8715857 222188 libdevel extra libt1-5-dbg_5.1.2-3+squeeze1_mips.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJPEpi1AAoJEKAUSqXS1Z2a5P4P/1U+lLElLhHM43yMhrTdvz7y 0qKfQ3wi5gczPI35ikF16ht8hatigvmJ73KdLwZchrB0w4DcfOhG3q4g8JbHPQN7 YI9kp0KcyQF9hQ1aTqWEBlP3tL6P/F5TXfkp44LTStJJonoYgHzRS7stpz5a8hU0 CPrpFAHI2IN5UgZpVABweqToK/AIrEF2BR3SJT0TVe+ftIXF2DpKH14YmA33s8on yws3D2jRRJRQUDxpyEd0eorclfz0AtyER/GchmVdoOQXu0fBvdmdPwKsmtALVHkF 6HmW6FrtR8F+CGx+UnEV9BpQ/hi8s9Bwp3ntfVGYXOuWj6H5+3pH6lQogwbgdpKP wjlPZbFKTb9k+q8CRSC9bkFfMaY5/6JA48+ZYIVGbHxk+neCk7cWUHRDuorUgP9X bjGAJBxUJSHMwnVfTKWEpGP7Rfn5MVNo/IF4gB7vk/fQ9fFWtgbf95JwW8/KnbAf kb0Cnn7j4L3QxXZ3ouHOeJR/pPRrmr/M/91h0ZVjeahfqIP42rqEXD7NnK4MPTrG 6VpNfkrL0z/yMeRbFYU7h8086tw4GPac7/QisVCfVE3oTkW6kEhP3U9Yleyz0aaW vPyhUNiHgVnYge7s6v78jiGpfl9nVAlRvfBzblQQxZF9DTzeTVghNJdeckHcuchx j3E50p36uz+jdkVuLVSU =6ypV -----END PGP SIGNATURE-----