-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 14 Jan 2012 21:55:47 +0100 Source: t1lib Binary: libt1-5 libt1-dev t1lib-bin libt1-doc libt1-5-dbg Architecture: s390 Version: 5.1.2-3+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: s390/s390x Build Daemon (zandonai) Changed-By: Yves-Alexis Perez Description: libt1-5 - Type 1 font rasterizer library - runtime libt1-5-dbg - Type 1 font rasterizer library - debugging runtime libt1-dev - Type 1 font rasterizer library - development libt1-doc - Type 1 font rasterizer library - developers documentation t1lib-bin - Type 1 font rasterizer library - user binaries Closes: 652996 Changes: t1lib (5.1.2-3+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * debian/patches: - CVE-2010-2642 added, fix heap-based buffer overflow first found in evince but applicable to the embedded afmparse library found in t1lib too. Fixes CVE-2011-0433 too on the same patch. - CVE-2011-0764 added, fix arbitrary code execution by only using ppoints when it is a valid pointer. closes: #652996 This fixes CVE-2011-0764, CVE-2011-1552, CVE-2011-1553 and CVE-2011-1554 * format-string added, fix a format string error IfTrace0 macro and another in T1_SubfsetFont(). Checksums-Sha1: 501dc5f48b48fb416f0c15eb6530b3708756e5f6 170034 libt1-5_5.1.2-3+squeeze1_s390.deb a0474be3f5eb50055869c9e45090a6c86d53822a 186298 libt1-dev_5.1.2-3+squeeze1_s390.deb ae20e91fb384be37d87e9fdfd937c1e54696ccc7 64702 t1lib-bin_5.1.2-3+squeeze1_s390.deb ab7e7966bfeb7b68dfe3940e25bb3b068180c47d 211004 libt1-5-dbg_5.1.2-3+squeeze1_s390.deb Checksums-Sha256: a7b1adccdec423e9034d21a8829cd052ee1092f7a38f7f82f0010633a86aa417 170034 libt1-5_5.1.2-3+squeeze1_s390.deb 63df195fb316428c4f95ad1f1e8296f790ee112249699a722127b85c0942a9ce 186298 libt1-dev_5.1.2-3+squeeze1_s390.deb 1f0a986774786f08519cacd1d223db9841b11533457a03df2a7d23d56cca2a0b 64702 t1lib-bin_5.1.2-3+squeeze1_s390.deb 4cef2eaeb841b6db800f6ec24e418caf91b97c53624941ed33311a525afd1bbc 211004 libt1-5-dbg_5.1.2-3+squeeze1_s390.deb Files: a626dc5bb21f06c3ec175b0c8086b97d 170034 libs optional libt1-5_5.1.2-3+squeeze1_s390.deb b40fbe937d8d03667d671e6d00e26a3e 186298 libdevel optional libt1-dev_5.1.2-3+squeeze1_s390.deb 00a7202aebee3ce3a0a843004e54fffa 64702 misc optional t1lib-bin_5.1.2-3+squeeze1_s390.deb 8ec1f8f97732d76064302a7d637df881 211004 libdevel extra libt1-5-dbg_5.1.2-3+squeeze1_s390.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJPEpdQAAoJELWkVFx3JxH3xbwQALVubFpPEzWML1Y/Lhqra286 LFjynOUV2bz8gMPGzp3qJSTe4XQARV3YkVBZr9QpJ1Yzpa6etvK/lLTcXT8cu0xU g+1brdhPTXgq2guSbyKLN4gUibnvSQAZV9kwT0cM/1zvpXegzKzExWIVFHZ1dOkh 8LTEwC06ogrb5IIk0jOQwtn4i9WDQz4GubItLwxLSwh+wEoi/LL9EbW2D+ozcsOw xuhRE7JVCIU51cWfBipUz9D5NWzu6EOUvH9heHk/y1LAEbO/q8Dwj3c5U0T4G3gv DMrU2pKpSzFBA8R10POloGlcXCdfp9J8mlcd8jBkyhufgzCDOB1BGAw9zxMP9CVP tJ3NKg1qZhyFL5/uUU5PbdXGk//rzcmWmVcdOTTjmfW42/p7kXaLC3nWWYRV9TwQ 1IxqyCI61TMx3hELPqT5WiBdcnSo8olXfbM+5sXZzf8SqLFc3bAJRzka1J6TISt1 5VP+K7O1iQ+cWV+sd/4BdWbw311a8Nmi9fnKQzPpSnBp0JIB/nlCdxqmkMEP9HnU OrPFn18N1N1/m8sU1z+Eo8Cwqqkz1g+uDz5ycIEM+sOsQCoBtuTSJWyWr0/IuhrU 4m+AO8CRv3PRO8Tkn8RejEgzz6DzCB+UzTrLBO871+jBPivHe1WRx0KMxh96xUjr z9TFBGgHd3ALeDHAmjta =JHFu -----END PGP SIGNATURE-----