-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 25 May 2025 17:51:18 +0200 Source: libavif Binary: libavif-bin libavif-bin-dbgsym libavif-dev libavif-gdk-pixbuf libavif-gdk-pixbuf-dbgsym libavif15 libavif15-dbgsym Architecture: ppc64el Version: 0.11.1-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Salvatore Bonaccorso Description: libavif-bin - Library for handling .avif files (utilities) libavif-dev - Library for handling .avif files (development files) libavif-gdk-pixbuf - Library for handling .avif files (GDK pixbuf plugin) libavif15 - Library for handling .avif files Closes: 1105883 1105885 Changes: libavif (0.11.1-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Add integer overflow checks to makeRoom (CVE-2025-48174) (Closes: #1105885) * Avoid integer overflow in (32-bit) int or unsigned int arithmetic operations (CVE-2025-48175) (Closes: #1105883) Checksums-Sha1: 897152c7c375549389de2b71c6e77e1d03c8b957 119176 libavif-bin-dbgsym_0.11.1-1+deb12u1_ppc64el.deb 5fe05fabcfa2b40cc977afea9dced10d0e7c3d44 61440 libavif-bin_0.11.1-1+deb12u1_ppc64el.deb 6d88f6f9e6753271eb7dd0376bea57d1a9fe4af4 41868 libavif-dev_0.11.1-1+deb12u1_ppc64el.deb b5b19f11aff49c32e8d7483a4447abfe1ec1a9a3 16992 libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_ppc64el.deb a739d3a8b49853a8462a5b3102dfbb9328b6ee91 28184 libavif-gdk-pixbuf_0.11.1-1+deb12u1_ppc64el.deb 3c7ddab056b919c0c0aa1d59b64d315ca3f11541 232476 libavif15-dbgsym_0.11.1-1+deb12u1_ppc64el.deb ddf6b7e7cbae70bf663017dec9cda1c50d2b4761 104964 libavif15_0.11.1-1+deb12u1_ppc64el.deb 7a0b28362bf22b0958ad35394c886ca88443ffaa 11821 libavif_0.11.1-1+deb12u1_ppc64el-buildd.buildinfo Checksums-Sha256: 1a52975750f1ca4a3203a50af769fb42814703620fbd1923fb63bf8b6702af84 119176 libavif-bin-dbgsym_0.11.1-1+deb12u1_ppc64el.deb 5457444132912eb1e04deaba877efc8505ae43353cb7e40c3e5cc191d32727e8 61440 libavif-bin_0.11.1-1+deb12u1_ppc64el.deb 80cd3150000c27a2ee6d88967a65bedd0e26c402eca2501b81cdc2386c9b9ddf 41868 libavif-dev_0.11.1-1+deb12u1_ppc64el.deb 0183c0498dc4293fbbad9109c17ec1f548928ee6ebda089d55141470ae93ef16 16992 libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_ppc64el.deb 97d42d3e3e3fd643076201981ac2d0a5040a4ac8525b41106f47788f455db124 28184 libavif-gdk-pixbuf_0.11.1-1+deb12u1_ppc64el.deb 8d3d558208ad099db5ffc3416c4d2c0aa78c07a4b742a80c60cf1a1a1ea0a305 232476 libavif15-dbgsym_0.11.1-1+deb12u1_ppc64el.deb 34c570ad2b8f908bca3f62521ee67b1b87705826dfae6fb78320c6cae33029e4 104964 libavif15_0.11.1-1+deb12u1_ppc64el.deb f72548ffa1871e2c9c09298fffd86ec52f49076742da22ce9d7585a229a54fe8 11821 libavif_0.11.1-1+deb12u1_ppc64el-buildd.buildinfo Files: 5b1ba7d7a078c0c4aa42bee7187199c7 119176 debug optional libavif-bin-dbgsym_0.11.1-1+deb12u1_ppc64el.deb 4c03ddd8fb1e80dd38ca3cda1194b12e 61440 utils optional libavif-bin_0.11.1-1+deb12u1_ppc64el.deb 3a62c16808fb3b74676c5b897c7e88bf 41868 libdevel optional libavif-dev_0.11.1-1+deb12u1_ppc64el.deb 154c11b5725c6f41bef57e3bb438c6e2 16992 debug optional libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_ppc64el.deb 3eb6bb11becb8dab58b1a2db0ecc36f4 28184 libs optional libavif-gdk-pixbuf_0.11.1-1+deb12u1_ppc64el.deb e9c83098e1b407cb0ff02685e9ce8e26 232476 debug optional libavif15-dbgsym_0.11.1-1+deb12u1_ppc64el.deb 91e1b10ad5129a7f32660c7c04778a39 104964 libs optional libavif15_0.11.1-1+deb12u1_ppc64el.deb f04ef7b4c196b57e49867abb5f28d5f0 11821 libs optional libavif_0.11.1-1+deb12u1_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZAv/jpGRqS40qyb11oy1TpxF0ZAFAmgzQkMACgkQ1oy1TpxF 0ZB7EA/9FAeqE8+fSs58mBLLOQ4LgDo52Bn/bSeyXrR9u5fDviIeuzViahX/OSfS IR1nIJSoiHh5nKHk0981Y88PqYEKpus+1KF7UciY1r+ANFXqdu2k5lBAmSvNvs8D xY5/68ytVYYrl8WBnG77HQjdqo6u0Iq2E53vlj9P7jNWRZfHydFloOu1LkhOLPKg soy5vUZqsmChlBIKJ9VIHD1DAZ9V+i4uSeGN1ugha0NkZluZzzgk6zVifpZqXKRD 2vV3bBxz/UgM6zxIP44MwFTK34SgsIDkKZ/1v1KaWq4xdKPWGIjrJNcd0VWB+qbd iDoO/QghS8qlgmgPUC9Hjd0oCusPo6zr6Apx/eS7oFzxsPSbJh43UwGEZnMDVmZF 1vtcUrlEGE7nil+S9YMEayu4D4QUzLqIMmb20xr00Z7eoRWfRb8wK7nW45dnZw4h JLuh1QcoiEALXOxGGg34Id3NQcljZHSm5taxYPkCKtOLlg8U0asmQ3KHB3m9KnQV wEQ0OVnn7tgHEBvZ8t7Mcbz19FcH8i7ZfClvO7Oyy8NGVRq3bV7/reVk0+d97fUo dkvzs2QdZVf9whaW0eGda1shhy2Oc6E/4VQ8OMGFRQ4nkcb+jEZa6cZ0syuza6uP 5B4S26zOGJp4BYlV5+TqipiIB33Kj6y5bsbmBIkPqSfTamz1Rwo= =1sxA -----END PGP SIGNATURE-----