Back to libwebp PTS page

Accepted libwebp 1.2.4-0.3 (source) into unstable



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Thu, 14 Sep 2023 17:44:43 +0200
Source: libwebp
Built-For-Profiles: noudeb
Architecture: source
Version: 1.2.4-0.3
Distribution: unstable
Urgency: medium
Maintainer: Jeff Breidenbach <jab@debian.org>
Changed-By: Gianfranco Costamagna <locutusofborg@debian.org>
Closes: 1051786
Changes:
 libwebp (1.2.4-0.3) unstable; urgency=medium
 .
   * Non-maintainer upload
 .
   [ Marc Deslauriers ]
   * SECURITY UPDATE: Heap buffer overflow in BuildHuffmanTable
     - debian/patches/CVE-2023-4863.patch: fix OOB write in
       BuildHuffmanTable in src/dec/vp8l_dec.c, src/dec/vp8li_dec.h,
       src/utils/huffman_utils.c, src/utils/huffman_utils.h.
     - CVE-2023-4863 (Closes: #1051786)
Checksums-Sha1:
 ae376370cf5af552dae5f4bacd56462998966e44 2379 libwebp_1.2.4-0.3.dsc
 024945f296f435689a3f866a6aac74e0ed50a4a5 12004 libwebp_1.2.4-0.3.debian.tar.xz
 83168a2c666b48f00c89f8a9218bc4bcacb65d47 8332 libwebp_1.2.4-0.3_source.buildinfo
Checksums-Sha256:
 822a6258c3d41b875a60e709c46cf739c55047b4b6d0e1541c5432a4fe445ec8 2379 libwebp_1.2.4-0.3.dsc
 e2196110d735d4020feefa38ca28abc6e87a3998c0ce9645dbc8745ac64dc20d 12004 libwebp_1.2.4-0.3.debian.tar.xz
 2726c5aef385361ea9ada8e518073f22c98ffbbffff2e733745d0ab13b4faac2 8332 libwebp_1.2.4-0.3_source.buildinfo
Files:
 7f4d117d960f22180d0ca71da228554c 2379 libs optional libwebp_1.2.4-0.3.dsc
 5e73b5b54e7e3f95350c56fe095a5544 12004 libs optional libwebp_1.2.4-0.3.debian.tar.xz
 a1b5290e27af3d4f7016423c2673b7dc 8332 libs optional libwebp_1.2.4-0.3_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEkpeKbhleSSGCX3/w808JdE6fXdkFAmUDKssACgkQ808JdE6f
XdnvZg//cIjSJTR7EB9bg4w2TuiIrO/S4gu27YBv2f81IE1ov7sa+44tMEbpKElx
wtQw4hI16JiwiE3FLOjAZ5JmW2ylTZ4pTachsewP19Lww351go9hlLlHv7ZqiL7F
1+YqycVuL3m50VAyN2lKIMbD+Y6wQnJeqhjvGkE6gFNIAx+Q4zLPY1rw+qXWIhpo
WIYZzMyrtGJtC/BrIdb+m4XvXjIiqzbMULT/SmbziRfQOFmtXN8aHUD9LqcFjAKC
EfvT7JWBbpPt2Z0G7vIsEvzFrdRkwvfiXqW+DfLK+/uh4uDHtZBa+tcpkgvVRoeF
j4VOWkMYx354E3RT82yYvyp+kescXNK8sg6+HwkjdHtP68I7rP257KjX2fIJ/y35
TTNNs98ujZPDP+EApeKEt+JhaZ8OP8Fs0O4xuaoo9h+ad6bQWJwSHpwxmh6xjGa9
ZmZ0Kyue+gtxSolrWp4g4nT2j6CYcqWRM1G1wnUh8knhMnbpz6fVb9IQdo24RAS4
Eha6sCeHJ7mGZ9rH2SeJcRwc6sGiVvwMnjkqZnJIQQ1X3A9YgZwsDeA9ze/v2/eN
uDNIDr8UcHw3d1vdbUtrqq1grCFNfCiOkfJjaFX+sBkKxZtD5y/wHuSLQZcq526Z
iRqve+DIU2eSxATofKhmFBHNxjUfsdNFcoeAPmdksiwAV4TUhEA=
=TYMj
-----END PGP SIGNATURE-----