-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: armel Version: 0.1+dfsg-4.2+deb13u1 Distribution: trixie Urgency: medium Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4.2+deb13u1) trixie; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: 16360450a1ec176f773afeba6ee3c01358c2aeed 20996 librlottie-dev_0.1+dfsg-4.2+deb13u1_armel.deb c5f386caba54f459703ff1eaddbb349afba40e7f 2036828 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_armel.deb bbff06cb0f9e0ff99495523936f9e014e1324381 111804 librlottie0-1_0.1+dfsg-4.2+deb13u1_armel.deb 8321fdf9e05a9a20a35a09956a3f36333b438487 7225 rlottie_0.1+dfsg-4.2+deb13u1_armel-buildd.buildinfo Checksums-Sha256: 68b653631b349f050693e692291f6f5de7aaf7af2e0cd824f2409d65a6a95dd3 20996 librlottie-dev_0.1+dfsg-4.2+deb13u1_armel.deb 4c3c2bfdbd9c049963046267fbf3707884c0a9158055ebd17a5733d792f94f1e 2036828 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_armel.deb 4fe79019aed7de269934df48d4dd9218bf558bccd272fe8fdf4190170124814e 111804 librlottie0-1_0.1+dfsg-4.2+deb13u1_armel.deb 796e775507c5b069262e0c44bcdbd5c2f2622421486abd30766636e0446f3b23 7225 rlottie_0.1+dfsg-4.2+deb13u1_armel-buildd.buildinfo Files: b08db0562bae92c43a7a174714decdcb 20996 libdevel optional librlottie-dev_0.1+dfsg-4.2+deb13u1_armel.deb 9c9066b642b0fe194479329827e81590 2036828 debug optional librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_armel.deb 946993d187246e56d44e3d98db5f24f2 111804 libs optional librlottie0-1_0.1+dfsg-4.2+deb13u1_armel.deb 55ffe9a6113d82e89d6d95e8ff6e1ac4 7225 libs optional rlottie_0.1+dfsg-4.2+deb13u1_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmlG1HAACgkQOQKMdMnE H5MFPhAA7u7iRAjKMs0AJ1CV7w48aOz35VLYeN/VrTDaAMJWynzgoG3/ngMpWtLQ t63zZyvqEmXH1nsW7Q/7yOD2ZHXBkrgTZ/qVGk12kuL6HKCW0PDpUA350qlwgSgB /5datU4X8x33Jd2Gh5NUUpOZVLtYmJmDNdJK8A+57brJubPliOB4e7q5uRfpvHI2 OslH1Cc/ntfA66ipXslCw9jwXpaehtBR9xT5Eldpg1SFnLmeGqnO0izmZf7ev5zM 2A4FfrgnHHs9U711otwV+DjyFuc8CkJLoZ0jSa1Ww4slyjESwL4j6RQwyqouUi98 q/wUJRjyYOA5lWBefEZUfxX7dGb8vTmOmP06wFftN5P6yLNJGdrfLiD9h3q1HKqg 2isjd3WZ7emRtUNBmlKSOTX5PDrNMenhKy/bx6l86Uiv35Po30fCFkH+KCuP7nOn r4jMqqKVY6C8sOKTSLAPNy37cfzN6jAGYS+CC5XpYTnzp2yxFHk8jHESOPAFTxXs qfHoQkayTZWQNwhThHOBnQSlGhzeMeVpKEPEoMZZ/SNS3IsAWVgwoGmHmNg5nIi5 SvpyKqN7onOD3IAJ7vqTxRPdI82pzab7NAKSzTUl+8sWbRRSJjxScCE5razjYdri weVEhqU/2zSkYGx6yFCNrw42x+2GAm0JiDL2KaQXb8wrroRozHw= =fxkJ -----END PGP SIGNATURE-----