-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: mips64el Version: 0.1+dfsg-4+deb12u1 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4+deb12u1) bookworm; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: af2c4c99e51a82648a0c062369e6d71fbd5aaca7 20852 librlottie-dev_0.1+dfsg-4+deb12u1_mips64el.deb f16cc5ec1f8d820006cc377dee60a1eac9b7f6d4 2540540 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_mips64el.deb 3f897a1d1483214a1946e79ecd2cb6d07a1d8308 167256 librlottie0-1_0.1+dfsg-4+deb12u1_mips64el.deb 517b28c5bdf111c9909213ae604cc7ddead0eb84 7384 rlottie_0.1+dfsg-4+deb12u1_mips64el-buildd.buildinfo Checksums-Sha256: 8d8a4e3907e68c1fd8ca1be4e74235e8e5df2511869d002b15e256b878c53706 20852 librlottie-dev_0.1+dfsg-4+deb12u1_mips64el.deb 4e876116a09c8521d9dc85cc4711a83110f340c9b649ab7f5b2993e773db2dd2 2540540 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_mips64el.deb d59fe20fb565496d51284ab68405d43ae70c9aa518805c42008f39b68d6c783e 167256 librlottie0-1_0.1+dfsg-4+deb12u1_mips64el.deb 209225d579c3eab75b34b4da37d1e725d6b6ac8ab5823ff486a98b7884c120a1 7384 rlottie_0.1+dfsg-4+deb12u1_mips64el-buildd.buildinfo Files: e348b9e98a68d3dee9c251debf514228 20852 libdevel optional librlottie-dev_0.1+dfsg-4+deb12u1_mips64el.deb b6da1f67f82da4476d43cc21389ddad7 2540540 debug optional librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_mips64el.deb 2aa907ec126d8f398a8718ca378ec143 167256 libs optional librlottie0-1_0.1+dfsg-4+deb12u1_mips64el.deb 1746c058d5383821617703006f122522 7384 libs optional rlottie_0.1+dfsg-4+deb12u1_mips64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYLhEzFkGpb3yYRVHmlVdU6AM9BUFAmlOp7MACgkQmlVdU6AM 9BV+ZQ//SZ7Dpe2tIYMb5V0n31rsofuBqrj1UMMbgXEz9jE43rd/1XUk8UbjoxRK N5qRXBCckxek8YS+tnL1ubZDSc3gXZp7l2PctT+8XNI55A4KqBRN81SV/oBGdgoS aD0ZsfyWp4MNOrXpF4rPMwSe3jQSUnTAySqMKlAQVySJ4tIxTU2qKlzfskg/6OMs SXY/acdSpOzt314jgPA81rvvQ3hVp74FbXT0Rrqp6u/FrPBk3ZinG8eivt7szdOh YT9mSHUtByD/EMZkwWb1eHCG0UDxkH5arcnuFOrCxhVyVX3MfBn7EqplggyA+MZc 6K4kIVu8LE7AVqMbwCCMcjXk6uo0YmSx6bZBxDQiJDsJiXQtr6V6G5ojneKQfDZs RfDEhArVjin9Xvn9pgYHSeHorz89oYLh2+hcX3ATyBjlXY3yktuhuT4clY+pyDdB Q3s/XwbmaOjNTHbimZ9uIFqWEMzHW8K4iyofbgZ0Kpd5JvM3qeSmr0Azl6ayduY6 yYhhj8uvdIKFHJ5uRO+rGNiY964HsLikG44N3HHvnf6lydVmumlpPQSkXcH4t5GJ WJQmWVPiaodMHP/SdgZwsTyWxG2kirY8uzjNeX9WSWZWWLfjEYztIQCArqstwQ7j MyVjulR8Ai0oo05DG6i+0+5VsMjVbbPLir/2HS1Z1zlj/Vpa7Gk= =M+Kq -----END PGP SIGNATURE-----