-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 25 May 2025 17:51:18 +0200 Source: libavif Binary: libavif-bin libavif-bin-dbgsym libavif-dev libavif-gdk-pixbuf libavif-gdk-pixbuf-dbgsym libavif15 libavif15-dbgsym Architecture: amd64 Version: 0.11.1-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Salvatore Bonaccorso Description: libavif-bin - Library for handling .avif files (utilities) libavif-dev - Library for handling .avif files (development files) libavif-gdk-pixbuf - Library for handling .avif files (GDK pixbuf plugin) libavif15 - Library for handling .avif files Closes: 1105883 1105885 Changes: libavif (0.11.1-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Add integer overflow checks to makeRoom (CVE-2025-48174) (Closes: #1105885) * Avoid integer overflow in (32-bit) int or unsigned int arithmetic operations (CVE-2025-48175) (Closes: #1105883) Checksums-Sha1: ed7db059f87e1c7fd1adf83aba473bfe8c8663cf 125288 libavif-bin-dbgsym_0.11.1-1+deb12u1_amd64.deb f1c1d2360cd205f2f90840f2697420e436dd3549 59212 libavif-bin_0.11.1-1+deb12u1_amd64.deb 3e662a21e3bbd12df90cc70a5fbde17a5d97c165 41868 libavif-dev_0.11.1-1+deb12u1_amd64.deb c30201cdf48e9027120df33d480d6811b3f26cde 16440 libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_amd64.deb b002e816c105b525f296ec720590fec37fecb9ec 27584 libavif-gdk-pixbuf_0.11.1-1+deb12u1_amd64.deb 4d21482885c6762dbb5badb9a96df78b7e523a30 228052 libavif15-dbgsym_0.11.1-1+deb12u1_amd64.deb e11e291822e9e7ba326c7ba45e68676dfacaffd4 94396 libavif15_0.11.1-1+deb12u1_amd64.deb 52a124e96bfac9b86981fbbc1ab5d756b88b70e8 11792 libavif_0.11.1-1+deb12u1_amd64-buildd.buildinfo Checksums-Sha256: 33da7af81cf399ca04d8702829a99322fb5bb67404a2e4b02d01b71b4d3e91d1 125288 libavif-bin-dbgsym_0.11.1-1+deb12u1_amd64.deb 8779c64d2b879a84091c94927692ce77a9a04e774f41b25805e9277218f805fc 59212 libavif-bin_0.11.1-1+deb12u1_amd64.deb 6fb8b2e351b8f4a8ff1e84fcdba59176597dc6c785b517360674ea5c54393477 41868 libavif-dev_0.11.1-1+deb12u1_amd64.deb aa2a9378da5aff9b981ec7fcb99772e09e1444ed59b48847c294fc86ec84650a 16440 libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_amd64.deb 1108d3de49a92fdd13343ba684967d9db3a23af0999be465956843d7a3461648 27584 libavif-gdk-pixbuf_0.11.1-1+deb12u1_amd64.deb e3167217c3e48d493e6df50ec0d9037d5cc1f435902a3dd1c9f0e42710b24b0e 228052 libavif15-dbgsym_0.11.1-1+deb12u1_amd64.deb c79d57f0f62d67d2353765592fb4f519119392befa53d27a34c9d0348cd580a3 94396 libavif15_0.11.1-1+deb12u1_amd64.deb 9e63eaf745d1b858568696eb12dd4b87caaa5b085f015eafc3a2fd04c5cf6383 11792 libavif_0.11.1-1+deb12u1_amd64-buildd.buildinfo Files: 9e83c5ace7727a50a62461625a8d5643 125288 debug optional libavif-bin-dbgsym_0.11.1-1+deb12u1_amd64.deb 6cf55dc705d905751c5df4309d243c0e 59212 utils optional libavif-bin_0.11.1-1+deb12u1_amd64.deb 10f8c9bbd6f06d7de213226791541f28 41868 libdevel optional libavif-dev_0.11.1-1+deb12u1_amd64.deb 7e4d16b714a2559b4bd55685ea32e4e3 16440 debug optional libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_amd64.deb 8d1141710d576ac5d74fec5407c4dbed 27584 libs optional libavif-gdk-pixbuf_0.11.1-1+deb12u1_amd64.deb bf03a4bc094a9df10809df6396f6410e 228052 debug optional libavif15-dbgsym_0.11.1-1+deb12u1_amd64.deb 1602a6b36075a904a0c712446c69ed30 94396 libs optional libavif15_0.11.1-1+deb12u1_amd64.deb 4ec4bac5bf441f0aaa78863e3071220a 11792 libs optional libavif_0.11.1-1+deb12u1_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEHqtYLkdKRyCY94K8fUw6/tXbAmMFAmgzQlYACgkQfUw6/tXb AmO4Yg//bT4o6jVicUkc57Q7GQq+5K8JScsVPIqxB3eBD+pI6WZFQf91jrIbS/Sl Nwk7YlHwEv987IKXFys4+XVptyX9iA8jkh992AF30kOj9qMjDlnVg1bRPwOUFSGk 3080c7OMuldtTriXhaL8gMwsLYapIJlVjdg7hnaIAxdT5Bih3JiCJ1vSD8d1GK4X ezn8P3TUJqNjg0mJkBFwY08Y90Dob3UkrvBr4Gmx8aCGqCP4RtX9yBEZZXRt2YkK ntTiLq56fnIeK6lsHsrjrGEMx5T3YiIYqCbY935TNfe8supK+uuQQ0gYlbLAy0KN E/Jq1D1nN7D1WFWzx2W34wOX6DeDnkCba4a6+jGg6HQu2AXFYqt08lw4m+ZGvK0O S1R+BBkQFX0Ia77vlXtNuO4g4LL7mfn39lYMsh9tzF+k5+G8U9f/rjYSyaw/nutr u3cqRy+XjCJ5pQa1wqwE6S9OaorV57qHfN5oqrDvIAwR81hxqbhBGJQK+udONld/ DFQiMeLxeSXbWcFDG0mBKihoLOcqHJHboHbj2VR4eo5YMPZKuQL1a4mOIf7AnuVj Uyk835bur0ec96nEjHBy5wKK1tPzdQrHTC6WhpU4hvGG2IMNkTqa0v6P+jmcX3W5 6L57wrQ7w/EMCSqBdB8kNIVGH6UUgI3ChyMmEcxJr0FRn2zC7V0= =SXep -----END PGP SIGNATURE-----