-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: ppc64el Version: 0.1+dfsg-4.2+deb13u1 Distribution: trixie Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4.2+deb13u1) trixie; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: 31e636ab59efda735589aec8ba5da66b95b215c1 21008 librlottie-dev_0.1+dfsg-4.2+deb13u1_ppc64el.deb 717bace62d8ee76ec8061053ddc17325cb750bdf 2025424 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_ppc64el.deb 55e9065485ab6e25dbdfe8a15f4104e64712a8cf 118316 librlottie0-1_0.1+dfsg-4.2+deb13u1_ppc64el.deb 533863a867e1bff144fa970330f604fbe5b5c9d4 7378 rlottie_0.1+dfsg-4.2+deb13u1_ppc64el-buildd.buildinfo Checksums-Sha256: d996fa66ca82177b86e7dfafa9f37aa8dfbd77f16d7a0e69e0d5a547815fde13 21008 librlottie-dev_0.1+dfsg-4.2+deb13u1_ppc64el.deb cf3ca95f64723aeeb15c2db6a19f63e4dc071ab3db02eb860f3a67abc9d3dcb2 2025424 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_ppc64el.deb 217846c5d7579910f6918cace451559fc6a4286e91e06fd07dac45d6e5387991 118316 librlottie0-1_0.1+dfsg-4.2+deb13u1_ppc64el.deb 6507538a1a7c8a074be07d9a7331272a1010d69439c4c8ee94bc000749e38a52 7378 rlottie_0.1+dfsg-4.2+deb13u1_ppc64el-buildd.buildinfo Files: 9d4e46c8b326d6a0f6e83cdbbcd99c28 21008 libdevel optional librlottie-dev_0.1+dfsg-4.2+deb13u1_ppc64el.deb e2af9f59d71d6c315698e17de762473c 2025424 debug optional librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_ppc64el.deb 929d68075cf0b8cab758ff228cceecc1 118316 libs optional librlottie0-1_0.1+dfsg-4.2+deb13u1_ppc64el.deb a1d20c8b2b726d644f3869c793918975 7378 libs optional rlottie_0.1+dfsg-4.2+deb13u1_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDoRc43uRWMOoIqIgDNLUPhbmg7MFAmlG1JAACgkQDNLUPhbm g7OlTBAAtZxy7lMrrDnERc6cuMq7RbYvbbSwDXUkMBuuEy6juV2IfQHM6eIL2CzQ LCPIh+3saGEcfjf2rn0QiBxlWugAKSo28GcmWO6LGvomS6N1R4FDIdWeKhJlocWk kDFBGaEH4jMrMyKWw8qo0WYIx9OlLjUmUOdqGIlLcoCI1rqsUB4/DkO30lOkjvQO 2cMSs00Ai2rO7jaU3PucKb6wvrRiDX9yO54/RLeNEh9trI8RSpQPcDhOnDM6Ine5 BhwfSyTVeSm/fuo+MLhO2cD9ghtm9tiEkLHmF/uFuNgrjv3eLi9Bph19oqpba20P IXDwA+DSzdce1nud3ykXUv6iqkCx3P9j0ER13GTkiAW7EBjIIRsK+4mkgbnrjCWa 4LV2KjJeT7Z6fdVa/79q+D4KOxV42URTg//mOCNev3UNNncYFlJ6+tvgx1i5r131 WYcHmkRYL8Qjk5XQgcqsxgsO6zxmpOpniglpWr8NNDj8FHNcTpFbx1PYL2Z4Pu26 8waUcyDjZUn/7u3gEPxUcgDceJ7p0jXNeMK+wON9gndf2QnnXjfbrv8D31YAh0h2 Ti+kJ9L7S+2/TRz08nGCOQSI3X33ycX+8WMuTrcKQGZXcJ4mmTdN8yPxnAomTHdr BFwvjmkj83e9dx9ieWjPRONVpA+duFrOyPNkYSBoiuIdkzJcPnc= =plcI -----END PGP SIGNATURE-----