-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: mipsel Version: 0.1+dfsg-4+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4+deb12u1) bookworm; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: 7aa8c47aac0d6732b89a77befa3bfad98b9b50ae 20844 librlottie-dev_0.1+dfsg-4+deb12u1_mipsel.deb 9ed80cb549ba12c3cd0a49f406fde5133324a37b 2502204 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_mipsel.deb 47f7f0b5128f9b90395108c49cc36793e3c46048 166508 librlottie0-1_0.1+dfsg-4+deb12u1_mipsel.deb 88e4a706578c3efb6d2a6a3032b68d71ac01f56b 7355 rlottie_0.1+dfsg-4+deb12u1_mipsel-buildd.buildinfo Checksums-Sha256: 7f8dcd37ea5cd6f1435e2710e7033af92d2f35e39c495f27cb3a285b656edfd6 20844 librlottie-dev_0.1+dfsg-4+deb12u1_mipsel.deb a3161301b0a6516d8a806e6c7f2f66cd9ec21b80cc77dbd4f3687bece55c9f42 2502204 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_mipsel.deb 5d603dd4fc646143be0210349f1b02c506cc1474224f930c7e847b4db5e1c43b 166508 librlottie0-1_0.1+dfsg-4+deb12u1_mipsel.deb fbd37d7a190665ec16dfa525e1950969dc132c30978839a6130f8beebc36af95 7355 rlottie_0.1+dfsg-4+deb12u1_mipsel-buildd.buildinfo Files: 68cdfd6dd22d609b870586988088e7e0 20844 libdevel optional librlottie-dev_0.1+dfsg-4+deb12u1_mipsel.deb 9bf0fcb11be2ade058272db1e0a1220a 2502204 debug optional librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_mipsel.deb ad63f737faee311e6b3a909bbc8d27a8 166508 libs optional librlottie0-1_0.1+dfsg-4+deb12u1_mipsel.deb a8d67e2d03f6cd24f6adbd5ebb225adf 7355 libs optional rlottie_0.1+dfsg-4+deb12u1_mipsel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYLhEzFkGpb3yYRVHmlVdU6AM9BUFAmlOpZoACgkQmlVdU6AM 9BXc8Q/+ItPGaMHHuZwD4U4gEwN2M8+qDGus+8qCasdkNbmwMCnkyKF9OMvffWKK 9A31SHijRBycH31aMJx88C+GfelIG4KoNWDXYJq07zWT2YEpt0uBfsyzeomsOxD7 IpXzhkDRPrZmkMOHuZOrFdJeKpt2EhqIvV+yuiIrPfPNcdyuDP+RWwoaiTgd3ws8 81SMdkV9atzKmQO5PlxYeCM3oo0GrvaQxcomiE1EfE8NLfD854D5o+bn8LrR/+Gu jRgx8I/aPd3FPg5gd9VxtxFh8gZEeq0qtvTtpoAuazIyU7bOuXGD6qesNfIxDJLY 8XA91mfo+YOyZB6L8i77OcSwB7p/MyQ5Eox5KRUfk+YP7N6+heR3OIhT4Qh2JZIh W8/Sy+5JfLQZYwSeS0HYjXydOEs/qTIOWDMhgi04lym6Ba/hda2ovIeZ9EpMQFl5 n/0KE7SGJ1EeK9S/N1jfMP8Kkk1OsjlFdDgbW0u/LtCj+rrzEH3GHAmDAbpBOB4l hgVBfoutieTZ7domfo6u8TgZQlcGlCs1oHIkQJbWW0XGvtvRtBF9Gsk+4dSiG+4q bSmr57psv0jhCokF+jpGngi56cqtVndbUl4oNViwAesGSJIHrraNtuXNesE8gNzr 50gfMqxWo9PFvted6mKe1THMTQUbooGKgriyGhF7abz/24Fi9dM= =KhNb -----END PGP SIGNATURE-----