-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 23 Feb 2018 11:03:17 +0100 Source: freexl Binary: libfreexl-dev libfreexl1 libfreexl1-dbg Architecture: i386 Version: 1.0.0g-1+deb8u5 Distribution: jessie-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Bas Couwenberg Description: libfreexl-dev - library for direct reading of Microsoft Excel spreadsheets - deve libfreexl1 - library for direct reading of Microsoft Excel spreadsheets libfreexl1-dbg - library for direct reading of Microsoft Excel spreadsheets - debu Changes: freexl (1.0.0g-1+deb8u5) jessie-security; urgency=high . * Add upstream patch to fix various heap-buffer-overflows. - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 Checksums-Sha1: 292e44ddc8c8b441b805b51adceceb96d91f3b9d 32802 libfreexl-dev_1.0.0g-1+deb8u5_i386.deb c824c14f6b2d89af0e4cbebe2e26afb9b7f10b93 28346 libfreexl1_1.0.0g-1+deb8u5_i386.deb b8e952ac495758c0abdbb671d6adcbfbcf58a1db 53186 libfreexl1-dbg_1.0.0g-1+deb8u5_i386.deb Checksums-Sha256: dc479f4910bacc481ab705866ee0f794fb88b45f18e888931ce9d82f716b12db 32802 libfreexl-dev_1.0.0g-1+deb8u5_i386.deb ef06cb091895274809ec51aca186c75abd27e435c7ffeda3d2caf2a3dc916ec8 28346 libfreexl1_1.0.0g-1+deb8u5_i386.deb a8df8417ff52df0417ab1351ec17349d34434f491a8b5ed5a4717d4c0f043644 53186 libfreexl1-dbg_1.0.0g-1+deb8u5_i386.deb Files: 950227e8e86f743c2b2083c62a92706a 32802 libdevel optional libfreexl-dev_1.0.0g-1+deb8u5_i386.deb d2a3bb94a2cf20dbe88116a95c27e11f 28346 libs optional libfreexl1_1.0.0g-1+deb8u5_i386.deb 45a6f9445dfcf1edae60df537a270f69 53186 debug extra libfreexl1-dbg_1.0.0g-1+deb8u5_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtf5havBwTlKSn3+I6LhVPZo19nYFAlqWUJkACgkQ6LhVPZo1 9nb1Ug//eebRBZYFVG+RKiTsc3G2sPc8mYfVU1MnKiEOJNtqpn+17XpLUuvlMYkj jkgv9fbngGsVkRYF4scdxvTk80qz0Rxsvhm4PEra6FYIc8PGwOShfn7IzCdOCTQs 2Swiolu86K0EY5dizPcmd1lVVGxcoC0VaIfnFbvjyYVRviBNVnku/NYPnGcCCo13 PO1xwSZEZm4ozB54b1J7DEuKiXO/1LqeOJUKOzH3aShOoRHgz04z6pa6DtL+3U/G yTSqy5+c8T5qTd2qfHPtUj1+BTtCX/4WxulEC18DQAU7V0OaG6wKrc3DeeUN+HOw KlZ/FerrfI0pxth3G2kfqEmfui9kUCOS9avHjECKhOOYbY7Oe2vFBpfmWpqFo5VZ rzJxFveYUno5MpLevgH0LsUQpyox/HPmblLEr6AvcQoxZTBR1NOkRAt59eYmYWZj trL6YW7B0q8iVlw1JlK1sSySyYuy4DHpOq5PCZwRJEnHrHddc3RjOyUv9DJic3TG nCBuMGjdW+piMAl8jiK4/WfFHNEuNIZjqpz5vKx4L35nJpmWOb0sV6nkBHqPyhPz M2TA5IwWXuHhW+dfx0JowsDE377aLz5X2eQVq2gvRf8F5O+iolHgqGtBA89HyJEv dHvGDnN4xMyy/GTmEr1enyS0EwX/4QfmfopJZ7tW62ZIFmHyTUM= =cUnm -----END PGP SIGNATURE-----