-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 03 Oct 2023 11:59:05 +0200 Source: libxpm Binary: libxpm-dev libxpm4 libxpm4-dbgsym xpmutils xpmutils-dbgsym Architecture: mipsel Version: 1:3.5.12-1.1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Julien Cristau Description: libxpm-dev - X11 pixmap library (development headers) libxpm4 - X11 pixmap library xpmutils - X11 pixmap utilities Changes: libxpm (1:3.5.12-1.1+deb11u1) bullseye-security; urgency=high . * CVE-2023-43788: out of bounds read in XpmCreateXpmImageFromBuffer() * CVE-2023-43789: out of bounds read on XPM with corrupted colormap * Avoid CVE-2023-43786: stack exhaustion in XPutImage() * Avoid CVE-2023-43787 (integer overflow in XCreateImage) Checksums-Sha1: 17811013a29bd130b15370718a8c400e9de92dfe 105680 libxpm-dev_3.5.12-1.1+deb11u1_mipsel.deb ed6fe23d60ddee3d0b497c763530388e0816c4ec 98572 libxpm4-dbgsym_3.5.12-1.1+deb11u1_mipsel.deb af2d9f1af9f14fc0dbd80c88f340ea3520bcef3c 45916 libxpm4_3.5.12-1.1+deb11u1_mipsel.deb 95b682a6b9428519c3e6bfb0d6214dcc3c2ade5b 7740 libxpm_3.5.12-1.1+deb11u1_mipsel-buildd.buildinfo 4cd22d82252f02680d23fa5ae4d60f5821686ad5 54492 xpmutils-dbgsym_3.5.12-1.1+deb11u1_mipsel.deb df7295bdbfec114536b13f8a92d7b0301bbd416a 38784 xpmutils_3.5.12-1.1+deb11u1_mipsel.deb Checksums-Sha256: 05832a4eb34671b597bc98ce6928993997d3b6992c2e348965fd38559d6973f6 105680 libxpm-dev_3.5.12-1.1+deb11u1_mipsel.deb 05a6712d4790fa01d9553f4e87e345819853f496ca1ce1aff17e5f088bbdb5ec 98572 libxpm4-dbgsym_3.5.12-1.1+deb11u1_mipsel.deb 43ef74320d08c3742d0fbad978fae994c6c14c258f7f33fbc8cee53e1dcab69d 45916 libxpm4_3.5.12-1.1+deb11u1_mipsel.deb 1c0907c67cc794574e21a8f2fb1f5ad2d555bd563e49c3ff6df55615f7463e60 7740 libxpm_3.5.12-1.1+deb11u1_mipsel-buildd.buildinfo 749c07fe5e0c752555288453fbe27b36b5ea348ce06802c526626fdd48e55eca 54492 xpmutils-dbgsym_3.5.12-1.1+deb11u1_mipsel.deb cbea1d3595cbbfe1c4566eafc8199957bbc7adfa3ae815e09d6bbefcf26078b0 38784 xpmutils_3.5.12-1.1+deb11u1_mipsel.deb Files: 06aa4d366e80ff5559fe102dacfbd754 105680 libdevel optional libxpm-dev_3.5.12-1.1+deb11u1_mipsel.deb d04740e460edc0ba576238d0ff6915bc 98572 debug optional libxpm4-dbgsym_3.5.12-1.1+deb11u1_mipsel.deb 71e566cc0ab841e7ae653e4521feee3f 45916 libs optional libxpm4_3.5.12-1.1+deb11u1_mipsel.deb d94481de403251907efcbb49cfd3288a 7740 x11 optional libxpm_3.5.12-1.1+deb11u1_mipsel-buildd.buildinfo bb0364daec7e9876fccc25e30dbcc972 54492 debug optional xpmutils-dbgsym_3.5.12-1.1+deb11u1_mipsel.deb 64a5d102513ed5afe20bc177df5cbc5a 38784 x11 optional xpmutils_3.5.12-1.1+deb11u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7FUbSrfgk+qhJhySoQbzkdO+xGgFAmUb7aQACgkQoQbzkdO+ xGhmhA//RHL9UAlPGezAVBCunNv0+35zuDh8qMXoDq0Noq2G1a9lH123Ci1leY51 +XgfeA7fSmxsd26w1XiPgsU4qYc8JWm7CXsSs+pYQUqgKw5u1b4EHeQsaBEi3PMS 1FdBOAxckk2bLxB3N40Q0KrFMva89EloO0iCwc3Cpgttl9fHOEdxuqJdG9/X95kg UyiNcBZp/BkrLnZmuGcXoQoEHS6SqYGi0k3fIIHmrQ/WYN8lesTrXxTzsbdZpiRz WXiNdspDrtiY2LO73zADmPv8taiXobu+MLx84cXAmgrwJL2KoGW/dyAmetzoKlaN evdIKd3NsgPPOTMsDhAcBMgsr4Gpe6aLndEeUXyETPkWpgKXbZzbGZizrVX4nvf9 8eS6ZPb7lCqltdwAcCtlIEU5w67pR+sLEQewjr5uLvOqv4b7sAIUFP4gvaK8Cwxl h0wvi9xgAehWlx4pr3a9/i996OBwvgjXU1Nrwzp6BjRFdiVMPcXcjzwoxlML691Y 6X89OPEG909c1cZAWSPR5VT4UjQ6FjFpSz3O0qbFnjDKqhacrW2UUbfNV446/a9E 1cr2OoKlEVQ4rWDjZUx1kUUrEZNIq1FiYm6eaip013UIdCAXJI5lvBQGbpviDEfM f5mwK5c8SYXukwaISMYlOxbIZ+EwRio+XMBYXQxc7IRbdhm+foo= =Fbn/ -----END PGP SIGNATURE-----