-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: s390x Version: 0.1+dfsg-4.2+deb13u1 Distribution: trixie Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4.2+deb13u1) trixie; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: 2e71037829c80067e4a0578f3c428a51b0c10efc 21004 librlottie-dev_0.1+dfsg-4.2+deb13u1_s390x.deb db3e8f2e2106cdb541a5a878e93a7c8396092064 2017416 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_s390x.deb 83cf423b34971ce86b998cbde14629baba07b000 112340 librlottie0-1_0.1+dfsg-4.2+deb13u1_s390x.deb a4f94286d064c1d6b45146197c0224b98dfef001 7235 rlottie_0.1+dfsg-4.2+deb13u1_s390x-buildd.buildinfo Checksums-Sha256: c33fc39a20cd9c4b0de988198a890251f2b06cb54162335999d4cd9ff12b77e6 21004 librlottie-dev_0.1+dfsg-4.2+deb13u1_s390x.deb 92aa044ccb3260b1419fc797fb57720475ae63313730a95214fe1d16d0fad27c 2017416 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_s390x.deb a2037acdd326b0aa37bfb5afbb79fd3de5874a2ebb1d013fb589f26f60093536 112340 librlottie0-1_0.1+dfsg-4.2+deb13u1_s390x.deb bfca344c28291c0f346f0093e2d321e5ca952fd8525edb5745d2e644f12b1b57 7235 rlottie_0.1+dfsg-4.2+deb13u1_s390x-buildd.buildinfo Files: 5e382251499007d49025d44605663b89 21004 libdevel optional librlottie-dev_0.1+dfsg-4.2+deb13u1_s390x.deb a2bad7961dac9048d10268266759ad8c 2017416 debug optional librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_s390x.deb 7671b34449a26e10acbcbd059b6ed287 112340 libs optional librlottie0-1_0.1+dfsg-4.2+deb13u1_s390x.deb 969a70ee7453983df81c5e34ae815eea 7235 libs optional rlottie_0.1+dfsg-4.2+deb13u1_s390x-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENly2ANlpa4eeqnluvVOPI7pYNpgFAmlG4owACgkQvVOPI7pY Npg41w/8Cymex2cVtkqhj/pCnRJBPbPlmsfukIuiagUEgM99mdXJvzr03hyXrSRY cHZyRFyxvP5coZGye8DlGmz45Bj28p82lt2B54vT34gL7vpOntfEmQhNxcWKhavX Tk8/3VnWe0Dmm8NrwvsxZppIR7qj0vFIISXWOXsaLAPQI/rj1MRsD3wkmaBLq0tg DAvWb5Up5Ak7z+k6fpLUwpzk5BFCObxezQO7+PtBEEJrXTdTYqjQvMiuQGbvdCTw DzhypoWFVJi3kLh9c9WtfPMTGE4emfQcygN3sZlhJceNs4dP+npWP6+Ym7+eA+ev nNRm71+swl5qM6+qssxgAaTC4/OHMUNMcery7A4go5q6+P2mGVjZAAh/AvgwEZet U2XBglLNnGJJ1x0iR8VqnMM5mMvmcSJVaXp2+0vfFU0Cei5VlR9TYE+4eU73WigV e9JOVCqHaaFnfx7T2EyIceqoAQ9247VQsTfFrydihq5TfNskpoYF7U/lEJ2DPCHx LzVKb8kCbyGe5tlyo4HBeyLYy+Ynyxx5RTQqw+kjgImSZGWLe2XmGuL3h76tIH02 rMxk8l1jb0sI+4g+kpD6KOk6dvukZ/36o6BxyAD2HBW/6260PtaN44++cU46XBxG 4ssqtW9vBQfU1sr5wbg/pQeVaok1raMiaFSiaIUAUVb/RxPMAok= =2bah -----END PGP SIGNATURE-----