-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 14 Jan 2012 21:55:47 +0100 Source: t1lib Binary: libt1-5 libt1-dev t1lib-bin libt1-doc libt1-5-dbg Architecture: mipsel Version: 5.1.2-3+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: mipsel Build Daemon (rem) Changed-By: Yves-Alexis Perez Description: libt1-5 - Type 1 font rasterizer library - runtime libt1-5-dbg - Type 1 font rasterizer library - debugging runtime libt1-dev - Type 1 font rasterizer library - development libt1-doc - Type 1 font rasterizer library - developers documentation t1lib-bin - Type 1 font rasterizer library - user binaries Closes: 652996 Changes: t1lib (5.1.2-3+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * debian/patches: - CVE-2010-2642 added, fix heap-based buffer overflow first found in evince but applicable to the embedded afmparse library found in t1lib too. Fixes CVE-2011-0433 too on the same patch. - CVE-2011-0764 added, fix arbitrary code execution by only using ppoints when it is a valid pointer. closes: #652996 This fixes CVE-2011-0764, CVE-2011-1552, CVE-2011-1553 and CVE-2011-1554 * format-string added, fix a format string error IfTrace0 macro and another in T1_SubfsetFont(). Checksums-Sha1: 25ed9755a435eda09652ddc0f0fe76658df76782 162724 libt1-5_5.1.2-3+squeeze1_mipsel.deb 1a8963731c3dd0fcd28022e7bca3029e8ee53620 217864 libt1-dev_5.1.2-3+squeeze1_mipsel.deb 73131d2d99cf700b97d0846d67b4e1ff59ef4978 55756 t1lib-bin_5.1.2-3+squeeze1_mipsel.deb b718cf513d2c31e6440da9801adee6d5950667c7 218714 libt1-5-dbg_5.1.2-3+squeeze1_mipsel.deb Checksums-Sha256: 4502f31eb5e24ae09a9cc8f8b1877250c9b935bcf075bdad744f9f3d51426d90 162724 libt1-5_5.1.2-3+squeeze1_mipsel.deb 8ea98b580a2152e4b00781b0fd2128262bae5ee9e575830289b7b5b5aea9b5f1 217864 libt1-dev_5.1.2-3+squeeze1_mipsel.deb cb44313c587c1b98176fb933b3755f61a8432d282e550717c1d5cc231c60678d 55756 t1lib-bin_5.1.2-3+squeeze1_mipsel.deb 315b3af482824b3121002a6c8fe2328c168a2b39b87574d4f0a07c43a971ec66 218714 libt1-5-dbg_5.1.2-3+squeeze1_mipsel.deb Files: f042e5f98afd646124b7d01c60265822 162724 libs optional libt1-5_5.1.2-3+squeeze1_mipsel.deb fd92426e93ceb33ded4316b2c8dfe8a1 217864 libdevel optional libt1-dev_5.1.2-3+squeeze1_mipsel.deb 3605e97b067270eeb5a6fc533d72d08c 55756 misc optional t1lib-bin_5.1.2-3+squeeze1_mipsel.deb 41c262c9c74c5285b89fc2e86418669d 218714 libdevel extra libt1-5-dbg_5.1.2-3+squeeze1_mipsel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJPEphbAAoJEAzzgj1nKIEulaMP/2uJhEzMMRRRhwkwk0odmEC2 toR4pkn0NZjJE2xpcrb8jOTglQzEfj+cpcmHW5vqXd3od5JZxLX2rdkLVz3jsHa0 qxl74/2TtqCESe0yaviMomJNL19AZ2GOMTtImla0BF1U+hjdDmSKOKGNnAZjcROA DFOUU4m/emadl0bqXeQpbnWCeT6yaDqv0GS2FHbsqu5K8X/2b8WNF1+Gw+v5cmkM 4CFBdWd/lMjx77xa/ZLLTYypYgUnwNRBmVybrqpVrExLH+m2/QA0UVhnjjtokE+7 IDi8COts/GF8PtUx1TowwumjKgfN/DkfLPkoGz0Oh50I6MoPOhfT9swz7184ES3S JHfflyxZb5lx/F+vo8XN2PQag8h1gt6DoraxtYDtO7lscAXrg6HF1+eLdzq2Y1ZR 4U56ECf0kAWx2qW92P6YQxFJvRRfoQPpQIQigN78WT6eN6Ahtb0ZqYsQsaXG7m6Q Y4WaSyD9aEN57QmyhO93zj/4uwypq+I9WolsWUlV7J3zMmxYgfmtrhOka9fSegVF 7YN+REhUzt7qI6+HCKtQKrpgt9YXHJzXOjUZND+nvJ7UeTkbgQdqI7oKK/nKs68q rJYkvKh1C9Ny6oLXahSI2dpT6d3CcAKyf8g8Zp1vbYZC5dHG8p7SkI/QpfeWu5em /KfZAvsfttVVG7D5mqYD =DZSO -----END PGP SIGNATURE-----