-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 15 Mar 2024 22:56:38 +0200 Source: fontforge Binary: fontforge fontforge-dbgsym fontforge-extras fontforge-extras-dbgsym fontforge-nox fontforge-nox-dbgsym libfontforge4 libfontforge4-dbgsym python3-fontforge python3-fontforge-dbgsym Architecture: i386 Version: 1:20201107~dfsg-4+deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Adrian Bunk Description: fontforge - font editor fontforge-extras - font editor - extra programs fontforge-nox - font editor - non-X version libfontforge4 - font editor - runtime library python3-fontforge - font editor - Python bindings Closes: 1064967 Changes: fontforge (1:20201107~dfsg-4+deb11u1) bullseye-security; urgency=medium . * Non-maintainer upload. * CVE-2024-25081: Spline Font command injection via crafted filenames * CVE-2024-25082: Spline Font command injection via crafted archives or compressed files * Closes: #1064967 Checksums-Sha1: 270dd40dca883361780ad46aaeb411a872f711ca 2428876 fontforge-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 878e1bb7973148fdda2338af925e02b72611bd43 338008 fontforge-extras-dbgsym_20201107~dfsg-4+deb11u1_i386.deb d8381269d2f0c2beb1155005c49762f97572444f 311412 fontforge-extras_20201107~dfsg-4+deb11u1_i386.deb 13f95ff7562a1863f706b1f61a91eda665a9af8d 7596 fontforge-nox-dbgsym_20201107~dfsg-4+deb11u1_i386.deb d6f658e63c897c57da599de3c2259f8e420573c6 39012 fontforge-nox_20201107~dfsg-4+deb11u1_i386.deb 4482bdd381ca46e2ddaa78a7305ed622799ae72b 18553 fontforge_20201107~dfsg-4+deb11u1_i386-buildd.buildinfo 8577f674fd0c91ed1886dcf1057965c3227a34a7 1418184 fontforge_20201107~dfsg-4+deb11u1_i386.deb 57b94699b8df43407625d9c00876441f37a2fbef 3562412 libfontforge4-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 63a6fe88afc63257922f766eae6fc086662838a7 1984808 libfontforge4_20201107~dfsg-4+deb11u1_i386.deb 16a5b5f45f80bb82211595c41d8a2fbc11e7ffc9 6272 python3-fontforge-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 3818990fea100cc902b08eee5582d8b2ad5a87b9 33724 python3-fontforge_20201107~dfsg-4+deb11u1_i386.deb Checksums-Sha256: dedee32a5fe0936a75b60f8dcffd586ceef23ec42f230002fb834f12302794e4 2428876 fontforge-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 0f13da0975a39ce582a4c6fd6887c5cad86a7af78b16d88b547be6c4a894433c 338008 fontforge-extras-dbgsym_20201107~dfsg-4+deb11u1_i386.deb bda008a4d5d6003008f86eef0b96f66dc5e2471485afe6a6af4f7f2fc3dfa29d 311412 fontforge-extras_20201107~dfsg-4+deb11u1_i386.deb a2f3d1631726477da8d653c45e15e34842202effa72c63477e078697b5df9e57 7596 fontforge-nox-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 1ee6bc896af00507383d20aead08fc207c11934d2d0fa2c2f3d3d07105c30a7a 39012 fontforge-nox_20201107~dfsg-4+deb11u1_i386.deb 3615b6980b5b9bdd511b02d5ba1a054af781cf88b94196ae259652a88f924eba 18553 fontforge_20201107~dfsg-4+deb11u1_i386-buildd.buildinfo 9346991a6b25712b19cb6d8c6e3cca1969292815b6bf28d049373d704cc329d6 1418184 fontforge_20201107~dfsg-4+deb11u1_i386.deb 88b2f97597107524c75290bfe3ed6b4063a2e57d50b9b6fc85d3326c94ddee84 3562412 libfontforge4-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 1d25ae80b982b67927e0bf259d6a765a7d89d900f983796bec1cf3b7262161c2 1984808 libfontforge4_20201107~dfsg-4+deb11u1_i386.deb 278eebd67f59b37a1e13b4c7df664a04eb3c763b817b0e6fca59ed10434a8ae5 6272 python3-fontforge-dbgsym_20201107~dfsg-4+deb11u1_i386.deb f125524fe288c92e5a206b955689ef41a561109bb1bfa946ec3af85b37d5871b 33724 python3-fontforge_20201107~dfsg-4+deb11u1_i386.deb Files: d20a319b5c9d433df041747a20471e5b 2428876 debug optional fontforge-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 1a860c5ec6258ae0ef864273e19a9e9e 338008 debug optional fontforge-extras-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 83727194fd6df0eb7964e5cad2a33964 311412 fonts optional fontforge-extras_20201107~dfsg-4+deb11u1_i386.deb 8b94169b4a84c66bdc185b6c5aeded12 7596 debug optional fontforge-nox-dbgsym_20201107~dfsg-4+deb11u1_i386.deb bf6895629af1593b16055d8d85eb12ed 39012 fonts optional fontforge-nox_20201107~dfsg-4+deb11u1_i386.deb 1f10ec1228a87e06803e049a3cbaefde 18553 fonts optional fontforge_20201107~dfsg-4+deb11u1_i386-buildd.buildinfo 16a062c7c79690f8b22517f3839a94af 1418184 fonts optional fontforge_20201107~dfsg-4+deb11u1_i386.deb b3549680748b2f6595d3543ccd7e2abb 3562412 debug optional libfontforge4-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 932ba7a5d8d1551652f69672f7ee41e0 1984808 libs optional libfontforge4_20201107~dfsg-4+deb11u1_i386.deb f056cfe8e4651e3df686a48f269ae86d 6272 debug optional python3-fontforge-dbgsym_20201107~dfsg-4+deb11u1_i386.deb 7c17088ff43655f699aac36e34a59d7c 33724 python optional python3-fontforge_20201107~dfsg-4+deb11u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJyRdn7p9tGRfxctAots23/koc0EFAmX1lE4ACgkQots23/ko c0HdXg//b6QqC12XRyJtaZ5z0rDTkS/rmbIwoGHBDb7ukgWfNN6eNmt1yNFd9YXn 2UZhw+ozizgTEL6QyWn9m0lKoYTzMEig4cj0h3Ir8nZ5Djbpo4xvuOVSxz2SN0yh Qq0lP67EI9OFcYZoXleEYYV6aphgoiOtzK2pBz2/MYWlsEJlXe4txQDdocgpyHLS TEK8Jiq9TxeA8x2+0iRzgGA7E2Epx4SznIvphlsLnswh168kQ/YZBJ1IF1KOzUWg hoUZn6Cl4KoSX+7b+SA58pfMndDsDNV7uSIB0Szg9AQLqQ/ujxRbzjZUkv+K6kw9 gIWZwWk/B/8DL8SgznhtyET5NRgVtCAkpezFJnWRIG+0lADgrE7Fth+3EfJW44cE biTDKXuegpZeBqGG9FqvR3ahffWvn9A44XdF6EZngO0wig4WsdK0BxlyUdLbbVf6 qMVUW8bMTwk9Nm6tYlLiWN08isV8y1Ch8a33+Z83Yzsdr6Yw2D0DrjvPjS8YM0ql LmSDnJXYWhDSuo2ypymkLSKzIfzuN2XN50QJlYn2CL5gmrbb3PWfeuWzK4HlkmR5 W2cmUSL5s1yxbT/v/aWqUw9feK9bsQ6PnDGtCdqhy1NRWBKdMi2kh1abyBoyUhkv qmitSMnaJtlooqj+GlVPcT6pVgD/Txeu70qifKSAolxx4yPebwU= =2CxS -----END PGP SIGNATURE-----