-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Jan 2025 11:39:12 +0200 Source: libtar Binary: libtar-dev libtar0 libtar0-dbgsym Architecture: i386 Version: 1.2.20-8+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Adrian Bunk Description: libtar-dev - C library for manipulating tar archives (development files) libtar0 - C library for manipulating tar archives Changes: libtar (1.2.20-8+deb12u1) bookworm; urgency=medium . * Non-maintainer upload. * CVE-2021-33643: out-of-bounds read in gnu_longlink() * CVE-2021-33644: out-of-bounds read in gnu_longname() * CVE-2021-33645: memory leak in th_read() * CVE-2021-33646: memory leak in th_read() Checksums-Sha1: b949aab764f8426b06d5762ea0fa9e1258b5d189 42252 libtar-dev_1.2.20-8+deb12u1_i386.deb a2e9542b748ea0240e7ece2cef8f46f7660c2f23 39268 libtar0-dbgsym_1.2.20-8+deb12u1_i386.deb 86cf9502dfa9577bee90def50383687b2bf75a81 22516 libtar0_1.2.20-8+deb12u1_i386.deb 0d2ad5a15a4727f2742e088d30127d4b3d6cc8df 6291 libtar_1.2.20-8+deb12u1_i386-buildd.buildinfo Checksums-Sha256: f24c52a074c3ba4477ec1b2f77b22f8378eaefa511b6d051153a4a146459bca1 42252 libtar-dev_1.2.20-8+deb12u1_i386.deb d0b8a8e542b54a3e98c003dedab0526cef87c5654f5bef5b4c967d8cb16f1c7e 39268 libtar0-dbgsym_1.2.20-8+deb12u1_i386.deb aba0694acc7f8d2404596c51022c6afd151bad8f891e0c8c7163294c24fecf3c 22516 libtar0_1.2.20-8+deb12u1_i386.deb 18233c3095715f34cc02ae4bea501a27a7c9fab457d33adcfd1f294ae6bb8460 6291 libtar_1.2.20-8+deb12u1_i386-buildd.buildinfo Files: 2fc5dbde29e6ec95ca71d5a0da821c6a 42252 libdevel optional libtar-dev_1.2.20-8+deb12u1_i386.deb e0f2da5a9e1a879bcbf0cdae9db090fe 39268 debug optional libtar0-dbgsym_1.2.20-8+deb12u1_i386.deb 7cfe055d649fff40ea029c5906499698 22516 libs optional libtar0_1.2.20-8+deb12u1_i386.deb b45544f1ee69115ad3e8a4ed4a40b5a6 6291 libs optional libtar_1.2.20-8+deb12u1_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErEDrIdpJkzFMm6K+PyQET5WCY90FAmeVIMYACgkQPyQET5WC Y90Nfw//bVytpYo6YKCccvJ9UPBTUFTQDNIB0+Dfsu+1bkMtLvRn93QKQn/FvYa7 gnanHBgnxgVDxmB/GvFq77BZXtVsIix5PuU8thazSmNDdZABvYyI+7jWpf9ZbF3L q2vONU8wEHPeVTX1ucNG5PbGJ0soYNWUsq08nmowCXjUN9w26Hy5NUH3rBUIUOM8 BgLJ4PUOUQvoUxSDa6FNDci2tAiX8GHTLsb0agNFX1wow5Y6JdMGluOsIOGTASvr OoS57NTMoSTJlYWEl6zTCCXweBSwzEyZYGzsbLFolPzeM0G9mx6VrjeIVMS49JxL UjuC3d4/pdQYQs+ugiDS9Dejg3x3JDv0qkKHkUUuMtgZkhLkFMWnD5bUDR7Sg9HG BZCFcFujtH7wmU6XssG6K/MKNp+iA6UVlTIH1q9mpxyLwrN3QdQN48G/fNkNO7Gu qh1RY8Q4cJSwG3uMheaeo6evWfLuC9bq2Ny3H96qg5iMjxuslFp5OpvDv7qldBw2 7FzS1/cITD13yyCS6Y3yV/HEPmlgfVl7eWXegKkM+y1Xmh9CklkhgCjz7Ey9HyRK FGkpWv+a4oNJ30bCXq/VoBSh5sfEi1Xddzx5sxEnZkLtQw58ViQxysdDC9nNBaqE xx2Xai41GHdWwwJNUXTJU8dkCwp3BTIl7ztP9BdiIE76ChQ07y8= =3nPI -----END PGP SIGNATURE-----