-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 25 May 2025 17:51:18 +0200 Source: libavif Binary: libavif-bin libavif-bin-dbgsym libavif-dev libavif-gdk-pixbuf libavif-gdk-pixbuf-dbgsym libavif15 libavif15-dbgsym Architecture: armhf Version: 0.11.1-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Salvatore Bonaccorso Description: libavif-bin - Library for handling .avif files (utilities) libavif-dev - Library for handling .avif files (development files) libavif-gdk-pixbuf - Library for handling .avif files (GDK pixbuf plugin) libavif15 - Library for handling .avif files Closes: 1105883 1105885 Changes: libavif (0.11.1-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Add integer overflow checks to makeRoom (CVE-2025-48174) (Closes: #1105885) * Avoid integer overflow in (32-bit) int or unsigned int arithmetic operations (CVE-2025-48175) (Closes: #1105883) Checksums-Sha1: b986c03303ec8925f482e6dc3cbdfa3f8e065704 119136 libavif-bin-dbgsym_0.11.1-1+deb12u1_armhf.deb 3fee3995560c0949678b8906839221640c6dfb73 56580 libavif-bin_0.11.1-1+deb12u1_armhf.deb dc4f05016cf427dc2905c9290066157a0a98ecd5 41872 libavif-dev_0.11.1-1+deb12u1_armhf.deb e9cc7500504e8664f68b6482af6c4124175e1d96 16648 libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_armhf.deb 76c5df104d676c7883f4290de0e30c18c306234c 26864 libavif-gdk-pixbuf_0.11.1-1+deb12u1_armhf.deb ddbfe1c05b816ec6c15f1fa000be63b58d457300 223320 libavif15-dbgsym_0.11.1-1+deb12u1_armhf.deb c393ec2216cb38a7077ff2de04c27de1ffa1e444 84892 libavif15_0.11.1-1+deb12u1_armhf.deb 558b0a96be550f04fb2d0979129b03edc856f1c8 11635 libavif_0.11.1-1+deb12u1_armhf-buildd.buildinfo Checksums-Sha256: 9d5f67441a78166aa12b8dcfe759e63b50c0555cf4aed1d5a5a45d2be0066ced 119136 libavif-bin-dbgsym_0.11.1-1+deb12u1_armhf.deb 73b45f1bbf8837d425f9ab6a1849d1a554352b6a37cf3e98080362b2e0515b03 56580 libavif-bin_0.11.1-1+deb12u1_armhf.deb bceeeff7712c8db2d321ae04e8bcb3e37660a7b70d404cdf9aede471cd1de9d4 41872 libavif-dev_0.11.1-1+deb12u1_armhf.deb 2b48a439b993f4b9e99ff35d7a54f994e556b2427744f98cf8a6cc16f1f76813 16648 libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_armhf.deb 6389c243e25241357d9fc98cb67d6291e5f8c85cde6035b894a295801ef0b214 26864 libavif-gdk-pixbuf_0.11.1-1+deb12u1_armhf.deb 6632d94c143d2a648a39285cae974e71d258ce138f545a3409b7f1b625522bf6 223320 libavif15-dbgsym_0.11.1-1+deb12u1_armhf.deb c6a432794de81d4573063157a40d6268a6bacdadcc4125d9da5f415fabd03221 84892 libavif15_0.11.1-1+deb12u1_armhf.deb 5fbb3dfb0d676bcd735ea2a5ccb76b9a7b70bc63c5b893470fe3b43c800cc7c2 11635 libavif_0.11.1-1+deb12u1_armhf-buildd.buildinfo Files: a9d085d6de349f17b41bdc914f7a7c1c 119136 debug optional libavif-bin-dbgsym_0.11.1-1+deb12u1_armhf.deb c80084c0409084ca2c902625087781a5 56580 utils optional libavif-bin_0.11.1-1+deb12u1_armhf.deb d7b8f446293120c44cb3543d8eebc7db 41872 libdevel optional libavif-dev_0.11.1-1+deb12u1_armhf.deb 07cd734cf3b2da927efa03af89ac4a70 16648 debug optional libavif-gdk-pixbuf-dbgsym_0.11.1-1+deb12u1_armhf.deb cebf261d75d1d5127c1656e17675306b 26864 libs optional libavif-gdk-pixbuf_0.11.1-1+deb12u1_armhf.deb a44b80bcc749d8a57f067f0515a9dfce 223320 debug optional libavif15-dbgsym_0.11.1-1+deb12u1_armhf.deb d0ac34ef4367947f6fd581114a3ef629 84892 libs optional libavif15_0.11.1-1+deb12u1_armhf.deb 6b1729f582ffb0534720ddf6c7ac6072 11635 libs optional libavif_0.11.1-1+deb12u1_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEegRwmIwj8f99iF4m4CwlMGxHD8UFAmgzQl0ACgkQ4CwlMGxH D8VOlhAAkqPwgAOIaKd+bgelbWrTHRuKw0dwCo9N0o1XvcFi/qSYVaYnN+ely2IC PsijgZZMyLg0Ytm53YdSM42gecoPs4s3DjgTmueBEQPHOjNf8z8KdvXuGVIj3770 FdWg5IDiuXWlvIYt9/xT8E6rEyC2OJvHEg1W5lj5S1B0gZ3GLZFKyFx+VvRyrKpL xtGK5I02PZh2Xb4cK7w8eytXkxzzYWduK8DvpROd5+orQrFlhRRIgvS/6UJVhgwJ uAsCbkfMOlmf+Bw/psCfIvYUqaStrD9SOfiZe2YeTNDtkhvKbVHfzISQN8h1ift0 qNwR3TuEN8Rt5zZIbe0iqjq5/lXAcq5lw60sEbXEWFeBT7FNMXH6chmDy5yOOLJe 3owUl/I9y7hnyyYwvbHAUlO3SXvjHMjvNZmrXov6bWyk6VsiKddd0kKqeFbVsygW HWBZkVTEkPj2wW+rJ2mcXbBbHhri6gQrJIGXsmMJ4Le9RhEPzw4ugjCr/W8lNQEI OVvhUNJnTivRtiP97XD7Fv+YnPPQNr6TbEq3a/dzBId0OXatyB6INaiYxvqJbAjq KxBd30COSK8KMDVcl+rtcI+CcDwfwLkQijSKgCYS6lDH8zEXHz/S2bZVhiAYNrJC 5SLie+XdPB9eX6ywqdEc4eQLk1f/rCTEMazlnNMuS6/HmpSrVps= =Dg90 -----END PGP SIGNATURE-----