-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Jan 2025 11:39:12 +0200 Source: libtar Binary: libtar-dev libtar0 libtar0-dbgsym Architecture: amd64 Version: 1.2.20-8+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Adrian Bunk Description: libtar-dev - C library for manipulating tar archives (development files) libtar0 - C library for manipulating tar archives Changes: libtar (1.2.20-8+deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * CVE-2021-33643: out-of-bounds read in gnu_longlink() * CVE-2021-33644: out-of-bounds read in gnu_longname() * CVE-2021-33645: memory leak in th_read() * CVE-2021-33646: memory leak in th_read() Checksums-Sha1: b9e8e4c9a59b451abfa97af7c257cfc984fb6c30 40272 libtar-dev_1.2.20-8+deb12u1_amd64.deb c36e5d93f38defb289a4f1b3c2840369c292bda5 45180 libtar0-dbgsym_1.2.20-8+deb12u1_amd64.deb 218cac0ca12fccb9bc77677486cc2648d6c63291 21200 libtar0_1.2.20-8+deb12u1_amd64.deb 7ce9e05f8468073e881bad6e884af6ba221335f0 6354 libtar_1.2.20-8+deb12u1_amd64-buildd.buildinfo Checksums-Sha256: 9ec6f2f2fa21f2ae252b3622f0b417037f97f4b9e22e5f718a473ce720062631 40272 libtar-dev_1.2.20-8+deb12u1_amd64.deb 356099fd4e95c61984c77ad40e03de484bf58cf75f7cf1290d72b3befe790504 45180 libtar0-dbgsym_1.2.20-8+deb12u1_amd64.deb 300018e862c0179f68af251ea22d0959b27f8aac2d8a43274bfc105cd3e56acc 21200 libtar0_1.2.20-8+deb12u1_amd64.deb b34ce2f6928bb4563684450857d984f782a84eb6ccc05d27c61148fde04e21cc 6354 libtar_1.2.20-8+deb12u1_amd64-buildd.buildinfo Files: e461e70659c29480b168cda8180a2962 40272 libdevel optional libtar-dev_1.2.20-8+deb12u1_amd64.deb b8da898c8e9ac2785a85b041ab73afce 45180 debug optional libtar0-dbgsym_1.2.20-8+deb12u1_amd64.deb 7e71cab7ac5f973f7983dd3b8d71e908 21200 libs optional libtar0_1.2.20-8+deb12u1_amd64.deb 42d9e74140c431e39c5e8a480e7df591 6354 libs optional libtar_1.2.20-8+deb12u1_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgdRoRGwEM09wlaMzOni7ZmUpKEcFAmeVIKAACgkQOni7ZmUp KEfvtw//damBLFsBcDIDBy9/pe+oyrc3gF8jRNG74aN76DZN46U7zTAVy5T0cZt4 uTU2T2fikeUZxE0TptAkT3wXyVazm2EKwLTKwXDH+PkxxYJK4PjXhTokXXqD+fQW em4F9QDteZ3RpdnlXAzTUAatnsCevVzQok0TTBxQsQ9FrbPET3qamGd+ifGE+cjt tp9RX3L/VYgpBWo4g8C+XW7toiLPvJwmBO+OSwcKwsVnof7ENRHluVO2bUTs4WoX B905gTIdmCf+k06SIY07axcDBnf4T7cmkWRG/NRzScDaBF0kLrdMmaBp/wKfHsJa VfM2+NSiJk4XQF26AoOJCfv0Kfl8yEv2hLvHPjS/LLSyZVrtZ18Q6xCRlwyVBy8Y 35m6vl+XQUwD8JQfBIhdAseAhZa/bP9R9Oek5+qCfObTD+JTpZlmLdBCHLPmOc3m 05S8JMbz205FHqGQ3bu1l5VXZfcPCgdSlIBIrhp3IXowS4pDDSf9AWtkd8Ygn2Du 3hmBBfcZL7LT8GUcBbVbFCA219rGiCuCGXE55E9vjKl+y2FHplkx5ymvLJqI2+0o rpovCPgmZ3OTznjxUAU73d3DzBqLboKZtwacvhmj/xED0GiiBvBbws43G2+qCpSy zSdUUUE6/0gXLkmcq383rz/IuSdO6+lyN0YGk6C6ATevUAC+jpI= =jVQG -----END PGP SIGNATURE-----