-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: i386 Version: 0.1+dfsg-4+deb12u1 Distribution: bookworm Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4+deb12u1) bookworm; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: 61d63e382b6a816dc47f5d2a18e5c98aa9ab2253 20840 librlottie-dev_0.1+dfsg-4+deb12u1_i386.deb 12b65e5c015554b579c8d88affb6527037a55342 2456052 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_i386.deb c987e06f3b52ec5f581065a7be9024bf52342a42 165220 librlottie0-1_0.1+dfsg-4+deb12u1_i386.deb b331a854e743700eb06a872b6921d9c3e2de2e9e 7492 rlottie_0.1+dfsg-4+deb12u1_i386-buildd.buildinfo Checksums-Sha256: 6abaa317f8ffb0293636aea7788fae96095995e8dcb4bb2df719b81ec4d5fcde 20840 librlottie-dev_0.1+dfsg-4+deb12u1_i386.deb 18bfc55b95269bb88451c6d2b786905c69f820b00a5741966894b74e35b5939b 2456052 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_i386.deb 645b168f5ee279ed1fba48084968d829e3cc247e6fd499d3d27727a4da5ddbc7 165220 librlottie0-1_0.1+dfsg-4+deb12u1_i386.deb 8a3d6b350c18ad157a35cbc90e305da675462c53b4d1fc872c91c3551a8a7ce6 7492 rlottie_0.1+dfsg-4+deb12u1_i386-buildd.buildinfo Files: 959c3a17c674dcb89033d4cafc06f703 20840 libdevel optional librlottie-dev_0.1+dfsg-4+deb12u1_i386.deb 7f5a55708e8423f451789a701dab7995 2456052 debug optional librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_i386.deb 726a2fb482aeb148039ee8a1d0888bc8 165220 libs optional librlottie0-1_0.1+dfsg-4+deb12u1_i386.deb d7f2cf9bf10dbf36d72423ee54429400 7492 libs optional rlottie_0.1+dfsg-4+deb12u1_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnw0rdzqckKx6dwRTEbCLukZn24oFAmlOpOQACgkQEbCLukZn 24pZ0Q/+IOB90yiTD04V1dHvZoS2g/8MV0kGgcNX+AguKj4ydlwfVwtcRZPySmhE GG79ebe2y/KTWq0oYVUV6A38ADn8Td3aGQ+OmPsBYoQwCCc+cWSO7McphOOmmHM1 Zw1vDgRXD3t2yup5AJiYASeHLDhP6nGBhSixxrWEvZX5T5NIGBkXcaGrmJTJLBKb koSHz1QVmDchzzICwLw8YNHbLjIcfbnw+msXGs09iVt7aBVXmfToYs3yNJBkzNNQ VNY589DvFHsqbKhCONnSY/FIuBmmPvCpPgRLRRExx0CailaHLNSMUNniWWwXgTVI 5ahpxDl3pS3SFCMbCFzrqhkZhVu1orLpfPy/IZ99XKqj8P6gzdNOCvzvwjyyLmut 23teQmQEG3GzT4Omr9UofDALdFtv4AzVoQAnrTtjTbXgfEbUE3wsnVmr8fV9VV5R tKIRVb+MFHRDHynkhNqRdNdbTkMF1iabQmdZXIzVqo2zzuMir9oRNzFr18wpcwBY tGBaLA4TR60z86Poi0RnuWDVEcbrKA9ztnpkpnTXfxe8IgvWbCy5D+1KIC6X4mwx nQ6ioX0XdQt2zjW3hJhBeLRzCgk7EFsS52jXBn6nhdmQ27I9Lac6vvO73wnLFExF XKdV6va7GXjsKc/U74cwMcZlONqSnnT3YcBEjvE3eMGuDPEsIKg= =5jh6 -----END PGP SIGNATURE-----