-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: arm64 Version: 0.1+dfsg-4+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-05) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4+deb12u1) bookworm; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: 36bf97247359f239f16a7f69df09cb7488efc6ac 20852 librlottie-dev_0.1+dfsg-4+deb12u1_arm64.deb 9e1d91d5daaaf327078260e76e8ac9f2838e4adf 2482064 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_arm64.deb 9d181ccf240dc5a779fbfaf2ee0ed0a1e7ca23d1 146836 librlottie0-1_0.1+dfsg-4+deb12u1_arm64.deb 06c55d14f7a907bc064c424f53f6eae245366e87 7570 rlottie_0.1+dfsg-4+deb12u1_arm64-buildd.buildinfo Checksums-Sha256: e89b7d7ffd4dd210d94c1912a6a3917677600d1fd28f3f0fa831b32bf605afa7 20852 librlottie-dev_0.1+dfsg-4+deb12u1_arm64.deb 17d560f37e3f4e1bb34b03267e68f21b2e034b00c30143bea5cae6c1fc8876c5 2482064 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_arm64.deb 722f1b295097f6feb1d10d0f2fe566da59199557fcaa2864947a1cdbde3fc92e 146836 librlottie0-1_0.1+dfsg-4+deb12u1_arm64.deb e6859981f41dcec3ff666dbbff49ad69f31790a1b970a6f4b2c5b93fe277fca3 7570 rlottie_0.1+dfsg-4+deb12u1_arm64-buildd.buildinfo Files: 900412285f3edb7e2c2c7beb051d183b 20852 libdevel optional librlottie-dev_0.1+dfsg-4+deb12u1_arm64.deb 1c3770721fa742fc3f089a70621978e6 2482064 debug optional librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_arm64.deb 0e3fbf0719d19692868d840f302529fc 146836 libs optional librlottie0-1_0.1+dfsg-4+deb12u1_arm64.deb 48536fcb5b946d928ce321ae21f78a5a 7570 libs optional rlottie_0.1+dfsg-4+deb12u1_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiIG3Q3DxwDgRKKeyLRECdjCZQkcFAmlOpF4ACgkQLRECdjCZ QkeEpxAAi1TNU5H9yasICmacQeGFoVBWAtGIbzjLYP/GzGqUgPutA4b+d2iSyQ7W WdrmbNW2gCDeI5kC73/skTVgClnNTkWbuj9h1x+16qquuUuakyUDNb7s661QMWZa XdIRKtAJbIqtz4i05/0lW+zLmtV47nF6ySKaVQ3BKV7Vt0yiqARxZYBL+V9OHo7c cKJzODG997wxAOW68hA+BqeaPhawHsAaVsfBigl3R3ReD+4Fg18stMNtc6M8tZGN hoLJCNwL8MPWksAQHpEbG2zB1QUMuwE5epl3rAwm+GLTMZArSM7c+ym0rLY7/LlO 3PuAqVHcFWiFVjetVHafl6LCVvx4SrWsn7y0yasLor2B53obPQ5675t2SnFoL4GM xQltETUPiQDO4Ix/tntadoclm77FcsMiQQj3uoI8MGW9Lwx/bpdNhZy1DfqxAnGq zZr1YyI90EZBarltN1TS+Inv1luvVeO/V3doaTUzu5lV/sowhptu8XAsPYhUjWVC wd9iYHKBS1Jn9kcPIWwUa7cJ2eQk/RSsgu/Byl2ebR0zB0SetpR6Qf2XxJrTGDTY xeG6d7EQBx9PVcdAzybGU3kL5Eaqpue02INlyR8Py1IlPdnUmzerjCb/qrb0s5v4 BknEeSHcfGwpNBHMmIW0ry97qAYw2ol2OV95y/4iEwwxc9Bmiqo= =auPp -----END PGP SIGNATURE-----