-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 25 May 2025 17:51:18 +0200 Source: libavif Binary: libavif-bin libavif-bin-dbgsym libavif-dev libavif-gdk-pixbuf libavif-gdk-pixbuf-dbgsym libavif15 libavif15-dbgsym Architecture: armel Version: 0.11.1-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Salvatore Bonaccorso Description: libavif-bin - Library for handling .avif files (utilities) libavif-dev - Library for handling .avif files (development files) libavif-gdk-pixbuf - Library for handling .avif files (GDK pixbuf plugin) libavif15 - Library for handling .avif files Closes: 1105883 1105885 Changes: libavif (0.11.1-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Add integer overflow checks to makeRoom (CVE-2025-48174) (Closes: #1105885) * Avoid integer overflow in (32-bit) int or unsigned int arithmetic operations (CVE-2025-48175) (Closes: #1105883) Checksums-Sha1: e88f962ec3f00ba1969c951023c9f89e56d5da6f 117100 libavif-bin-dbgsym_0.11.1-1+deb12u1_armel.deb 67ed2f983e70353d4d08dcdd19fc8941ae02e988 55708 libavif-bin_0.11.1-1+deb12u1_armel.deb 1d7b8c40cf34d0ede7cf769e6f10edbca1fb9a0e 41868 libavif-dev_0.11.1-1+deb12u1_armel.deb e8e3e59c0dc59f95e8e0ff9971cbafe7a5a3ed5a 16992 libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_armel.deb 0c87218d8b676832fd95ffe320a4819a2e8968d1 28288 libavif-gdk-pixbuf_0.11.1-1+deb12u1_armel.deb 71659bd9ed46e627776db95e1936eccb2f4ae865 224092 libavif15-dbgsym_0.11.1-1+deb12u1_armel.deb a83dcf8b8480563e9d067726e8d7a75247747dbb 87160 libavif15_0.11.1-1+deb12u1_armel.deb 4626672387c52ffc0dd94688ca619ba98b2bca73 11633 libavif_0.11.1-1+deb12u1_armel-buildd.buildinfo Checksums-Sha256: 8db91f0f4a9e5f4498ea30b0e5a8abe979ecb33927f951e9123053018146a149 117100 libavif-bin-dbgsym_0.11.1-1+deb12u1_armel.deb ab7072b62bf27fe3a81196830bc5abbff97ecf70220a4e1908ca28e264c0ee1f 55708 libavif-bin_0.11.1-1+deb12u1_armel.deb 5ec9e75a87a14cfb14249c073292176581660d1e8f870d2573c93b6261103f3f 41868 libavif-dev_0.11.1-1+deb12u1_armel.deb f8493253168b62c2caccff1a723ac90f85d129ea51f6c14310c8cd8e1d5925e9 16992 libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_armel.deb 3809ae6a28e1a6354148cb78e2159afe521650b33336356f0234a1da8b15cb0b 28288 libavif-gdk-pixbuf_0.11.1-1+deb12u1_armel.deb 3e02ab5b77ee718e59225fe442ff1be60126454ad429370c0f4ba568b6f38fae 224092 libavif15-dbgsym_0.11.1-1+deb12u1_armel.deb 9331a39bf942b849f189cc5e6bb521adabb3b510fc6e99c74587ffcd5af9f35e 87160 libavif15_0.11.1-1+deb12u1_armel.deb 90a34984c5e81ebe55b3744ede43635543d594803f8cacd41121e5383ce26e7c 11633 libavif_0.11.1-1+deb12u1_armel-buildd.buildinfo Files: 25eb851e11912fc67f7643439d045487 117100 debug optional libavif-bin-dbgsym_0.11.1-1+deb12u1_armel.deb 2dd2c23a8983130ab2bdd1bf4fc7145f 55708 utils optional libavif-bin_0.11.1-1+deb12u1_armel.deb 447a88e16bce461f1061d2f8ed9a6b82 41868 libdevel optional libavif-dev_0.11.1-1+deb12u1_armel.deb a22b6d4775e39cf65fa783fc985f520c 16992 debug optional libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_armel.deb 5dddd809b6aefc83380531d857480b7e 28288 libs optional libavif-gdk-pixbuf_0.11.1-1+deb12u1_armel.deb cce159eb28047a55abdea439611131cc 224092 debug optional libavif15-dbgsym_0.11.1-1+deb12u1_armel.deb d2a109590b7f78b77a90bc7f77224f97 87160 libs optional libavif15_0.11.1-1+deb12u1_armel.deb 64ff8246481bac30912d7a67554c4606 11633 libs optional libavif_0.11.1-1+deb12u1_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEVM4SKBZumztS8zr3lST9Us03ywsFAmgzQnEACgkQlST9Us03 ywsC4Q/+MUYWDtKf7ZCvO2xXcwCZ5tv8FsoajZ+rtAuSJtk81d3JRFNVLW7yfkLU 7CWijq3SKRKJ44j2s+NnzDswSTwuWynmwVK/vGYHKtpf7gOcJQ8/buXu2YZCix+9 36/zjH2+TtMIuW4rQd3+5u3CJiBrKzVAtYL0wVFq+p+Uf77s67QKG+ULr4XReftd fwN0CeQUyyMHyWl+v5K79IVXv4/GwDsNVDOy9Tlnr+Iwkofopn/yFFRiooBLMG2U ER+BQFNt1isYd9sSf3jugHu2fxOuCO3pb2JD5gK7vsx5tkG1nr9l1NH4HfSZK59w kDdV3d86KSGTHPZJnwVyL0NyzhNSbu9dwOsfjPcb0IZHMmVf9/jIWVGLWk4QzFDe tkVxAiKUnItCjPWgG4xpG1dsTP6JtKutdGNOUXI0QITSF2agIDNnLVAJwV9pJXHK ZqwRXfHFPQx0H8fHOAuILZ4OLV3Ttt5sjG9uBaxWiA9E6uYV/ScNTVd0pyiUxpiE hBBTeUMDgmr5r3Q72pYowmzCKcqLla17UAVYAzk6jp3+Kq1gKiSkDzAnr18449nX K7Up5KtInUpZV5bm+Tsx6U39TAWxPdR/iBqy71L2LteCFcSFYyjt4JlN0IbgyIFt 2LNQIsv09dGMcOJLkzLEeUev/9WMbOF0YvFaUu/VrwXbknqqBSs= =yFoA -----END PGP SIGNATURE-----