-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 03 Oct 2023 11:59:05 +0200 Source: libxpm Binary: libxpm-dev libxpm4 libxpm4-dbgsym xpmutils xpmutils-dbgsym Architecture: amd64 Version: 1:3.5.12-1.1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Julien Cristau Description: libxpm-dev - X11 pixmap library (development headers) libxpm4 - X11 pixmap library xpmutils - X11 pixmap utilities Changes: libxpm (1:3.5.12-1.1+deb11u1) bullseye-security; urgency=high . * CVE-2023-43788: out of bounds read in XpmCreateXpmImageFromBuffer() * CVE-2023-43789: out of bounds read on XPM with corrupted colormap * Avoid CVE-2023-43786: stack exhaustion in XPutImage() * Avoid CVE-2023-43787 (integer overflow in XCreateImage) Checksums-Sha1: ec3af11676c694cc38d3d95e0b29dfb5211ef62a 105184 libxpm-dev_3.5.12-1.1+deb11u1_amd64.deb e0a37b74b49442ba3db7d70e03c11b391e13b20d 103728 libxpm4-dbgsym_3.5.12-1.1+deb11u1_amd64.deb 63ef5e7a2eddea55924205e3a6cac60f61210ebb 50004 libxpm4_3.5.12-1.1+deb11u1_amd64.deb 19bb3a097177f7e3cbfe0c0d62deb7b6d6561c51 7877 libxpm_3.5.12-1.1+deb11u1_amd64-buildd.buildinfo bf9fd50a36605d53e87015359885fe17b2156f5e 55236 xpmutils-dbgsym_3.5.12-1.1+deb11u1_amd64.deb 41c23273092a7a92b000d47e1b395e7e5e28e3ad 39840 xpmutils_3.5.12-1.1+deb11u1_amd64.deb Checksums-Sha256: 3cc1ac7b68811ea68a9f28ce989d2cb5530cd7eb898de249cb147ce81d28d3c4 105184 libxpm-dev_3.5.12-1.1+deb11u1_amd64.deb f9b697763113e22b528671b3c2509220b0c48eca0c9ccf9c547eb67e4e69d27f 103728 libxpm4-dbgsym_3.5.12-1.1+deb11u1_amd64.deb 349a5a8cf0de6cb33c199027abfbd6b7a13f5160948e6db066a96080c61e4819 50004 libxpm4_3.5.12-1.1+deb11u1_amd64.deb ca63f4b2b4b7d259267a6959c9a86bf08299dedcea46d74a7d6983dbf70e8158 7877 libxpm_3.5.12-1.1+deb11u1_amd64-buildd.buildinfo ff4c6bc468cf29df86cbebd58b81e3382d4b99c9b70f5a48491770555025aa7e 55236 xpmutils-dbgsym_3.5.12-1.1+deb11u1_amd64.deb e961110cf28e05547860c964137e7029c2c003f72e0251226585c1a6e1939efc 39840 xpmutils_3.5.12-1.1+deb11u1_amd64.deb Files: 5429cb095a1c5f38a45a61aa19858201 105184 libdevel optional libxpm-dev_3.5.12-1.1+deb11u1_amd64.deb ba3a1acdd4d5e6f6448bb67411b8a2cc 103728 debug optional libxpm4-dbgsym_3.5.12-1.1+deb11u1_amd64.deb 4b85ffdd929da42c9892083abc962f06 50004 libs optional libxpm4_3.5.12-1.1+deb11u1_amd64.deb 4e9e3390f77c04f30027477dbe30a0be 7877 x11 optional libxpm_3.5.12-1.1+deb11u1_amd64-buildd.buildinfo b565e8a821cff3479fa58bb838363140 55236 debug optional xpmutils-dbgsym_3.5.12-1.1+deb11u1_amd64.deb 01b1cc62916e9b90dec6e23b94b0843d 39840 x11 optional xpmutils_3.5.12-1.1+deb11u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEi/TVpVg0yb7dq8QfDZWW6X29YdoFAmUb7RMACgkQDZWW6X29 YdosgxAAp905wDcDD8e2/GJ3hEIBdJaqEpIqiOMGYF+WvOeMcxt9d9ee9gM7BibP txlkWkw9ID9lhftHjXAVDas6bMPoe55kys0xs2t/ZrqqpCtMAay63X6NkLDx4IyT 1Xq+eb3mz8VFIHuUdaEcuEj38xVqHHxmZw5i0l1O00QUcrPjem5FQdr7ZQVg3rrJ cmNn42xhRwox7lW0PlHPfXCQs2OY0rEW0nG+1luK0FlgSXNprnif11JloEh0swNp Q850ptAgyHCIau6S0GL7AJIv7RRZWvp7jiaMI8UYkin5jCXr3AZmwTwkO2uExcRE ZSAIXt+VDwnhpQ1NZXMhnpiGd/kTLehSNccfmDr/6YlK8QlP4GLBozSHgJAmNms0 ICOBgDVPt4MYyRxtkP6ZLRtcVY0G4MC/9rqJoqMjw8ziUwwTiDBqlvwSWS32EEp2 4Ddt5vglvVywUHrmO68JOOh4rl2ZrHVVCLafCOWyFrMAMF5Kvnz0Lsqwmz5lGT3N DzlHUtJ5IhM3My6cLna8SoCEh8x+VG1ReHhbKNpqiW0F96zRRhFcNBlx/Xt5SatK qAvxC+2WVwiGpXE93wZP4hF/sR4cWC56la4s3rHboSFEY9ohiR5kYAsVXQ59bq4L yXNQYFWDptBbHMscF3+WeuOtk1E31e47jqDawQtbAVomySSILoI= =zdCw -----END PGP SIGNATURE-----