-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: armel Version: 0.1+dfsg-4+deb12u1 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-05) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4+deb12u1) bookworm; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: 170d788a1a42be67d968cc5affd2d0175ce27b2a 20852 librlottie-dev_0.1+dfsg-4+deb12u1_armel.deb 208b07e608f474b3e44dab59e06eddf8a7fdd813 2485304 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_armel.deb cd1806b904632d06632bcff9db5ae8b6bf079374 148960 librlottie0-1_0.1+dfsg-4+deb12u1_armel.deb 02f7a22e62ccc9d0072c5296af667a0a3e571937 7412 rlottie_0.1+dfsg-4+deb12u1_armel-buildd.buildinfo Checksums-Sha256: e5d9dc7c0de60e220c777e8a6ec860a55b49cc9d90a03161ff07dd2f9cec5135 20852 librlottie-dev_0.1+dfsg-4+deb12u1_armel.deb db22901f0d859e1c69a424b0697f1d0313208545f6011f590eac1fa413d38d6e 2485304 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_armel.deb 54537a637a66a5dbf2669e1df9399706774cf10d24bae7909fc6306259b19917 148960 librlottie0-1_0.1+dfsg-4+deb12u1_armel.deb b53cdfb78ab347a560a7990e6ad69a8d2ab8af8eb71594253b9624d937f4ca8b 7412 rlottie_0.1+dfsg-4+deb12u1_armel-buildd.buildinfo Files: 3b5d866f19b29b8f13fe4846446c6d1d 20852 libdevel optional librlottie-dev_0.1+dfsg-4+deb12u1_armel.deb 342c8a013ce6104f993bcf8a479f4d87 2485304 debug optional librlottie0-1-dbgsym_0.1+dfsg-4+deb12u1_armel.deb 3f4f4e6c200c266267ee9db52a74507a 148960 libs optional librlottie0-1_0.1+dfsg-4+deb12u1_armel.deb e708304e23c3795852345f2cca6f34ee 7412 libs optional rlottie_0.1+dfsg-4+deb12u1_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiIG3Q3DxwDgRKKeyLRECdjCZQkcFAmlOpJYACgkQLRECdjCZ QkdCkA/+KXniWx1t8i6UQupXhIRpsLvHQZMLXwJluZnJKyuFPcpoGr7sciEnd0Bs RLQWffddUjmKqK6aYk4FOgLO9oVbF33Rp7Iy5Q23Yl23znYyFiIvXv4/XvfgT52M fFN3Q93GuS+z8TTmKPIh1Vuao0TAmq6JlZ8eVFA/DOuEfQe3uZ23KnUgeMld9zCl ho2hmiZQQ07YGl0IX8aLyXjYJwDLjefBg7Y8HS18KEdN3lloXSGcgFdYnBF0k6BS ioa6gWyAR3/nnrPCwJHptwBtvgKj2JghACC0+SY3Un73uI8TP8o2jimYrkFZeHK/ MVqKCH0L/+j6OAGk2ODWqQo70/mywXYOE3t6eRMjcoAQ1fBcTY3rXDO5u/HZcz5W 7e9wc696X/1ZsPKszc+vCpujpDoO982+Zn7ee6GXJwA0qOi3uyICMNt6hmTNyhCS 5JBgU6Y8WotYFHiD6m7sV4GdLqw7IN3X3HuAeV9exGSRP663ayBmJCoS7PzvEdIj sLhFvTpfHj29Q8RSKmZfAbzJ5sOGZsZPsMQ1zq+cbtQS9HoQqf3ypgRvEvKLLORm UgRq0otFVko/BxbtG19pA6L03NQu6FM2ZgWk2oXkKh4kg3P6lg+lrCetaIIEC+h7 lD9g0MFf2WSmnim994N5qbLwD/WHw7FeIkxzo44tyEI9oZ4mJQw= =5Lbs -----END PGP SIGNATURE-----