-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 14 Jan 2012 21:55:47 +0100 Source: t1lib Binary: libt1-5 libt1-dev t1lib-bin libt1-doc libt1-5-dbg Architecture: powerpc Version: 5.1.2-3+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: powerpc Build Daemon (poulenc) Changed-By: Yves-Alexis Perez Description: libt1-5 - Type 1 font rasterizer library - runtime libt1-5-dbg - Type 1 font rasterizer library - debugging runtime libt1-dev - Type 1 font rasterizer library - development libt1-doc - Type 1 font rasterizer library - developers documentation t1lib-bin - Type 1 font rasterizer library - user binaries Closes: 652996 Changes: t1lib (5.1.2-3+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * debian/patches: - CVE-2010-2642 added, fix heap-based buffer overflow first found in evince but applicable to the embedded afmparse library found in t1lib too. Fixes CVE-2011-0433 too on the same patch. - CVE-2011-0764 added, fix arbitrary code execution by only using ppoints when it is a valid pointer. closes: #652996 This fixes CVE-2011-0764, CVE-2011-1552, CVE-2011-1553 and CVE-2011-1554 * format-string added, fix a format string error IfTrace0 macro and another in T1_SubfsetFont(). Checksums-Sha1: 919149b14653486a7b9c70f1c2082e336e7581b2 165690 libt1-5_5.1.2-3+squeeze1_powerpc.deb f9538405c7f763a9cfb25fecd078e6ed2708a8e9 203702 libt1-dev_5.1.2-3+squeeze1_powerpc.deb dff5a77459092ac7ecf985515e853d26d1842dc0 55856 t1lib-bin_5.1.2-3+squeeze1_powerpc.deb 036066304bfedd9cd5ddb056c6b3fde1a6a8583e 219794 libt1-5-dbg_5.1.2-3+squeeze1_powerpc.deb Checksums-Sha256: e8e6eadf33499ea13d9261ec477ea53866fa7421484e2d7e9bb06d0ce475d4ce 165690 libt1-5_5.1.2-3+squeeze1_powerpc.deb d7acaf0aedb848172e2c212ad90172f4a0238ad09a85391b073bf3e45b96440b 203702 libt1-dev_5.1.2-3+squeeze1_powerpc.deb 107db327a84823b9f6d836f5f81815a5220b7f550466be0a12933dfe57f242e1 55856 t1lib-bin_5.1.2-3+squeeze1_powerpc.deb 38382a7a6bf22e5845d01d59da90c383be94ecca623671034618857b379ea8f0 219794 libt1-5-dbg_5.1.2-3+squeeze1_powerpc.deb Files: 8ef023ade227b07108cc13faf89535e9 165690 libs optional libt1-5_5.1.2-3+squeeze1_powerpc.deb 4cf98715e9cee54d1df4136a9b4951fb 203702 libdevel optional libt1-dev_5.1.2-3+squeeze1_powerpc.deb 66ee3f9c54ee054959bc12029297e17b 55856 misc optional t1lib-bin_5.1.2-3+squeeze1_powerpc.deb 568cc41e83a13d4d33ee731439c66b45 219794 libdevel extra libt1-5-dbg_5.1.2-3+squeeze1_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJPEpcHAAoJEAEba0y9vvHNfeUQANIbOd3NkRJzzcJUeCA+1PiU L+Nf65O0/vkpGN38jMAG2tBRApk3jkIL4qgxpztMP0B8MC7S9zFELb+BW2ZAJHFn CZfiu+6RfXEsCGd3CSXvzHvMio7FuiDmMifcLw0ylnZ8/oloWnZUakjxlCBqXadQ WWVcrtsLYGucyEOvfDZmFFzEprjmTzcX3K4s2R/QQzxFgVAj8DDo4c9q/Wpzm9IG jJqNLIrhG61xoSPOpUDFvz0oPYfRsNiJPZkfy0s5REVo30snLey/cRwSDaIkAZyZ GdGNh4QOpG8rr7hyn+90I6yu6LYV2tuBnI8AhFHYBYEPaaXQyat3xQ24RivPQGo2 PBRhgxKs64VElr+js38sw701JMlSwLhgIxu1qelXZgMeOHwZNnJR6QAoMG3hCCSH 8c+K2YRbc45N4gzPnszy4Qo3mmCVUqJA1JIIuwdKdwuyBYUhNwb/m6Mdvhf126v5 F47e6ph67+ppO3sCMLzszAwgzB4NqnQDfoWXuUew9CsoT1MnshwQ9qBA7b+lnL+v A7iqJQHjZv4xyN+NGFhLgYkLoggDO+2n6b7EJCLCxwZsxzOmUHLtxL2UIAMv7nW1 uXFc4FMk97jq0pbetkrUmLOeLm7fze8pSJQFrR3aoCTTH1S+JiqwdGIo7ikxo2hv BCPulVURz7OylvxDrOGa =aZ4h -----END PGP SIGNATURE-----