-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 10 Nov 2024 16:26:42 +0100 Source: mpg123 Binary: libmpg123-0 libmpg123-0-dbgsym libmpg123-dev libout123-0 libout123-0-dbgsym libsyn123-0 libsyn123-0-dbgsym mpg123 mpg123-dbgsym Architecture: arm64 Version: 1.31.2-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: Salvatore Bonaccorso Description: libmpg123-0 - MPEG layer 1/2/3 audio decoder (shared library) libmpg123-dev - MPEG layer 1/2/3 audio decoder (development files) libout123-0 - MPEG layer 1/2/3 audio decoder (libout123 shared library) libsyn123-0 - MPEG layer 1/2/3 audio decoder (libsyn123 shared library) mpg123 - MPEG layer 1/2/3 audio player Closes: 1086443 Changes: mpg123 (1.31.2-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix buffer overflow (Frankenstein's Monster) (CVE-2024-10573) (Closes: #1086443) Checksums-Sha1: e43e842a5418d74ae60b86b5fc5daebbf34fa2c9 246172 libmpg123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb fbe4c806a57b4c9d88bdfe27717238ad962019b1 140704 libmpg123-0_1.31.2-1+deb12u1_arm64.deb 32a899aa3e912fd489210393409616a5d4f639ea 57556 libmpg123-dev_1.31.2-1+deb12u1_arm64.deb d45249bcab37915b174b74d1ded5905b59d4c9b0 74060 libout123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb 5fecab7da895fd6efd473e6796ee8b41f334ed3c 27048 libout123-0_1.31.2-1+deb12u1_arm64.deb b8bb42f8d35df37b8da83cefb64e3c4dca053482 164780 libsyn123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb c1916f88f02be3b8fe85f92a8ea134df90bbc142 82716 libsyn123-0_1.31.2-1+deb12u1_arm64.deb f25669b366ae0e81e853333d2e251286ad138f3b 325204 mpg123-dbgsym_1.31.2-1+deb12u1_arm64.deb 0c7a9ee8e100f5388eeccf86e450866d676ff45d 10523 mpg123_1.31.2-1+deb12u1_arm64-buildd.buildinfo ff62901b106ba887557b56c4b2580ee3db4e1c85 200592 mpg123_1.31.2-1+deb12u1_arm64.deb Checksums-Sha256: 227bb1a294ff92149c8605fcd7468d5e38d6f424a585f89ae943d0da8d58377e 246172 libmpg123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb a4348cc2939baabb498158c94229941d09fc42070af765dc45ef9b26eab727d2 140704 libmpg123-0_1.31.2-1+deb12u1_arm64.deb a9cbcdbc8f42605d8a0022b5c96bdcdcfd17f7187be42471b18f16de1e5b0029 57556 libmpg123-dev_1.31.2-1+deb12u1_arm64.deb 9d5a32e955cb3f785bfc9868f7d5ddfcde44e19512dbd717286ad97af108bf77 74060 libout123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb 94627869751802d50059c1d4fab115208a6d5b20bec2066b1efe703ddce9c0e8 27048 libout123-0_1.31.2-1+deb12u1_arm64.deb 236a924f4c1759fb61a6a50d2507f9ccb7003a38521f6bcb125ed2d541bdb265 164780 libsyn123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb 6a6abd9c3031c1f5c5b924922adb6db2bceb0ca62effe6da869c1cd9abee2146 82716 libsyn123-0_1.31.2-1+deb12u1_arm64.deb f68d381dd0ff3a7a55032f1647086f5da052e7c47e6a543e01cccea476d1b5b2 325204 mpg123-dbgsym_1.31.2-1+deb12u1_arm64.deb 43c1674f8d08519be24c416ba6513134d6d0ba52e3ca0de68a9b57366a4eef71 10523 mpg123_1.31.2-1+deb12u1_arm64-buildd.buildinfo 19f4573b529bed3460543726bfc02fd0b5c22c35c286b8ddcd17b072432c3f90 200592 mpg123_1.31.2-1+deb12u1_arm64.deb Files: e3424933d3474f3f2f6af66394b2454d 246172 debug optional libmpg123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb 914083307e607393db834c713efa8c6d 140704 libs optional libmpg123-0_1.31.2-1+deb12u1_arm64.deb 1cdaaf5f416f9cdb87e62796e532f5f1 57556 libdevel optional libmpg123-dev_1.31.2-1+deb12u1_arm64.deb 41d9aea4a582e7b1256ef2748262e91c 74060 debug optional libout123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb f75ce110eb770d508c733f2f7830b662 27048 libs optional libout123-0_1.31.2-1+deb12u1_arm64.deb 91294e1fa21d8c2d1f127f9f2318394b 164780 debug optional libsyn123-0-dbgsym_1.31.2-1+deb12u1_arm64.deb 69b76b1ddadb9e6fd2b1f4dce1b71d67 82716 libs optional libsyn123-0_1.31.2-1+deb12u1_arm64.deb 560ed6e4ae4947cbbf6649706864d44a 325204 debug optional mpg123-dbgsym_1.31.2-1+deb12u1_arm64.deb 21bc6343599f22e8acf960d832eedca0 10523 sound optional mpg123_1.31.2-1+deb12u1_arm64-buildd.buildinfo 283bbe29ae94846927ac20a9f470f830 200592 sound optional mpg123_1.31.2-1+deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE9C4sZYDxwNo9XoUDaRWK3AIe28EFAmcw1j4ACgkQaRWK3AIe 28E4/w//XqPkY7EgRu8d7JIpuBvmTFyvFLVKxqILaf6mH1lM2lFQivxoK+BqSIlA dtB2ywCv38CtQRgAO80JYrKIg3znt3pcahBnyCzkd+G0kYqcAtwPz5q4S8viINu0 rmbvA98oHtSaC3yw/tfeSrkV3U8vBe3KEmMYorXWXuvjGk4sZzrzi5fzKy/DyO95 xMrXJJEE+L4sc43TkixMVnb+Tz7MHS12uZGVWzpLX34KeDafqJ3a3onOpXSdqB5M ThmTT2emdANeTxF8UDapP9tBcP6n9WlU/fBprceQRtgYV5vppKvadQXWf8k24aXf vVvB5YdgRHenyH+JRG/01BXXrmlOH2UAeMCm2uIKY9nniVUURXd0M5VTSryVL1DZ FXMGzUSTignnVKGhkL1hMRjjFs08BmXhB9E+/owrSoI5IEOVgG6rEhiQNB+W8KNM xvIE3HaoNdL08eJ81PQfWPhlKbZVjG342OYWudc+VILjmWH3IPMe2vZfhtzr1OVo vjrFHA6R3ZtqLzlVpiKSCeJYA56aQYsdFKZFHP3Ht3z4K5yPHkP4iqEXQvfgMo9/ F6Qmz+5dVdc7/vxkqlshi/OxntuWvEV+5pf68Vf0hiwM466ofRANlMyu6CfHLVxP XFurFobnmolG+e8ARTKf+eKD/X6QRoOlIUGRr6cyevndH8cXb3A= =qkE8 -----END PGP SIGNATURE-----