-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 16 Mar 2018 21:00:34 +0100 Source: libvorbisidec Binary: libvorbisidec-dev libvorbisidec1 Architecture: i386 Version: 1.0.2+svn18153-1+deb9u1 Distribution: stretch-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Salvatore Bonaccorso Description: libvorbisidec-dev - Integer-only Ogg Vorbis decoder, AKA "tremor" (Development Files) libvorbisidec1 - Integer-only Ogg Vorbis decoder, AKA "tremor" Closes: 893132 Changes: libvorbisidec (1.0.2+svn18153-1+deb9u1) stretch-security; urgency=high . * Non-maintainer upload by the Security Team. * Prevent out-of-bounds write in codebook decoding (CVE-2018-5147) (Closes: #893132) Checksums-Sha1: 5ca777f149b6ae36be142a3f5ebe04edf2c71a98 99562 libvorbisidec-dev_1.0.2+svn18153-1+deb9u1_i386.deb 987f21415ed82ba762e2281d57340ed24526c81c 4200 libvorbisidec1-dbgsym_1.0.2+svn18153-1+deb9u1_i386.deb 329c8098d7b65a30b7b54ef1035bf28ed2b12256 74914 libvorbisidec1_1.0.2+svn18153-1+deb9u1_i386.deb f8f872a261ad7c3d8e8a4de7b555e94e85f3e69e 6737 libvorbisidec_1.0.2+svn18153-1+deb9u1_i386.buildinfo Checksums-Sha256: 2907dad489b145c02e6e2329e611d721df127a3fad59fc85169495e687a7ef9f 99562 libvorbisidec-dev_1.0.2+svn18153-1+deb9u1_i386.deb af155bf2db4899cc182ee1cfc9326395c701481f8584ef3ab5c7a8672e555cb1 4200 libvorbisidec1-dbgsym_1.0.2+svn18153-1+deb9u1_i386.deb 3cdc47934eb13449f366894948f80cfac8d8783b338dc0a3e187a5cb1df6072c 74914 libvorbisidec1_1.0.2+svn18153-1+deb9u1_i386.deb bdcefaca48ea803fdb7c96e039b86ec2a40f17309339372151631f942b08e123 6737 libvorbisidec_1.0.2+svn18153-1+deb9u1_i386.buildinfo Files: a45271fabbcb243e83df88f429b82ca0 99562 libdevel extra libvorbisidec-dev_1.0.2+svn18153-1+deb9u1_i386.deb 97574f33491a8f6c6d312720921fa051 4200 debug extra libvorbisidec1-dbgsym_1.0.2+svn18153-1+deb9u1_i386.deb ed6d2f1507d2d805a26b42d108fbcaad 74914 libs extra libvorbisidec1_1.0.2+svn18153-1+deb9u1_i386.deb fc89142179c3754f9a3bef9fbeed9eb4 6737 libs extra libvorbisidec_1.0.2+svn18153-1+deb9u1_i386.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEevHXPYnWIBOaTTctFfcBBC0/C0gFAlqsJlEACgkQFfcBBC0/ C0ixPA/+J9Hzc9qVk++KrtTNDJ9UhaEIp7lBz286uwhH9mJz7IYEEDe2pP2PcD+O RnPk74ocLLYLPuhSJhpBqu7vFDTDOraxj0wrgoHsauUWimz/nIQpHNaLCHhs02c9 ykOmhZF6h6m1XZmEdfXRYeA0LRQU7ak7D8P4O7+nepkK+sRHWTAXmOBCv3sRRE3j rb9uPueK0VytJeqHLpSUuDdBerMYfG0tzRF5ggID9lm9cv4FM5Wnf5d2h8/UxUzH rIYHqiJfvTWbTuWtMy7MDaLK/KK+6DUJK/WzEzdijGysS8hJU9wK+QEx9twkYiBs pt/d3iYW3XdCo7ElKCpiGKsqcLjfBcbEWvCnYGxeqTkpnyVRnPE4jnxOQJLDBdD2 fQwqK3x7+jG0Mpxq5Z2Y/x1W9DATXUZNJk5pmS6jYYftV7ezsj/MenGUGF1HXAIG DT661HzyBNYWv8VFenNd6UY/7yoBlNOtKmtcdaqmBIkNkxQpWXEnJIDHPVLSSWgS tSGW1HwIcX7hZVOeNBrxLrJoOnEGfCvewMKLbXQw3gv94EeEcyUZ8ASNeFxEXoFy mm36HhjLvmTXhDBg7YjypUh4uIOlJeg739gZ/ZrMQ26kiW1Zemrv8YudKZVUzNsp rAcdb2cu099K8b1pUVPLZosf4+preYIUMvWKxunI16ksXyGBIM4= =0bHu -----END PGP SIGNATURE-----