-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 3.0 (quilt) Source: icu Binary: libicu48, libicu48-dbg, libicu-dev, icu-doc Architecture: any all Version: 4.8.1.1-12+deb7u2 Maintainer: Jay Berkenbilt <[email protected]> Homepage: http://www.icu-project.org Standards-Version: 3.9.3 Build-Depends: cdbs (>= 0.4.93~), debhelper (>> 9~), dpkg-dev (>= 1.16.1~), doxygen (>= 1.7.1), hardening-wrapper Package-List: icu-doc deb doc optional libicu-dev deb libdevel optional libicu48 deb libs optional libicu48-dbg deb debug extra Checksums-Sha1: 7146ee269b39273fa98d750f73136b14f781758a 18675781 icu_4.8.1.1.orig.tar.gz 5e6792e2a456b66fc788c7972f546719a1c6a7db 195940 icu_4.8.1.1-12+deb7u2.debian.tar.gz Checksums-Sha256: 0a70491c5fdfc5a0fa7429f820da73951e07d59a268b3d8ffe052eec65820ca1 18675781 icu_4.8.1.1.orig.tar.gz 8629b1f3a3333923f9cfb30aba2615152633d7b4e6a9b24723847175a33a9ac2 195940 icu_4.8.1.1-12+deb7u2.debian.tar.gz Files: ea93970a0275be6b42f56953cd332c17 18675781 icu_4.8.1.1.orig.tar.gz 4a825ad16f8b2cf9ca3dd7b27d64d587 195940 icu_4.8.1.1-12+deb7u2.debian.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQQcBAEBCgAGBQJVBO4VAAoJELjWss0C1vRzzuAf/iAjyXTAFeBTzkLtLxqdvjp8 8QK5wrkKzXtnjaKsJw+ja6OyOc0byz0hhv59QKV/+cXWCdztPcv69kT37gEtFvSo kIO3ITCg/llxIFbSFtYa/KbCdIS+KrNDMMbe6K6S6J7mt/IM3vSaHoDxQxZ+/9NX xBuRu/Ogsi3bN6kVdyVUcMKPwJhtUk12rU4ipUPuWDvGJ6nfYcuofovYVPegcqTs /KOAV69HW2YerP+BqM2Pnf4O6hyQLbPFg/H/IZHJewxLJnAPyy81cCZ2fpcY4wyy I9QP2qBTBkYnSeKWtskNQ5E5YyJUBpF9pwopvR+3KE6LXyJ1CcHcQrHtcsxAYjef IrIIcqFo88WikJ7nJJrneBMCQnSf70uOKlctrN5GaH8yyJIzcsEl0Ktd91G0PZwD TZ0G2nXAloTRTfCF0vU+QfYsEg11kUrhRHrSbzFUu56IqAifYE1tGyO9PIvxleFd 5XrZ18gnypCGUtcb7IGaLGW3TpG/T7faKKY7l9YuyFAveAHu6P/iwIXWu9qY3CMq XcoQwdAtVwFcorgEn3DVLOeYsalsz3oZdVnLGIbZDogPlcVSvB1RXK2wiGz0sHwc TJ4keb6UriZLEv7ruE309Azhv/x8PfFHAKALelwnMFDwxuTpuWW1BhvVGfHZ5aCn R3aRQ1MUYJiq3vdWpZJfIR1/HxUVMW0GNVXYhWYwsCa6nKjZO1U2MwK2cnD1bhOR Ml1IbfV538BKRvZE8sCEgWex/CFEim/1BBU2pGdp2RH1+iQ5Z07eJKFMB5GmurOX d3wMoBKhCnKEy/2wKUEUtMECTogPjWx2TPgMv3geJoAAa4WKYTZFbp0nCc3nwz0s L2gNkIrE/AS/SnEjpCSA4sBJyZc8RoGbiysepZIrlmvHujtExmD/2y0G65CCbWGr OiH8A1V/t2XG93+3+aaX0hyH6ewgZgMdNZLTUbz55Cv1a+tQA1lR+tiB3gPRilDX TSeSRciia54MG2RaPcaD5NfHky3NAvZWTUwN0qWSwAH6x4OJhcEs/dH5h0VcDvub jgwM2jRYiGY88AIb4jXK9ZcHKmF5O3obmnR5oOMcQ/Kx+05vltYPIzst2xFaX9Mh RUWPAus0iz3xpAwFMfDQ7Z6liLXglpAWMjdgGG6a0yY2fcVuM/9OSJStW1EpYVlF cwqUOM3oqE3qTajp5U0f3I2waQq0FcjW4qYmiV/8CGXUD2SzLLtkAiwX4ajtfWA4 Jsj+FH+H2raUmYYIPk+HUktj7ZTfgt/AgUGSnKnAUc5kV3pWeoqZnYZm7/T7/xWN lWpGqD0ZlrcIGBzgz62oeSKTyiDA/UEapyjYBytCXYsTm6Zhkkj3fxx7IWooYhE= =QU1k -----END PGP SIGNATURE----- Changes: icu (4.8.1.1-12+deb7u2) stable-security; urgency=high * Non-maintainer upload by the Security Team. - Thanks to Marc Deslauriers for many of the backports. * Backport of icu's new layout engine. - Fixes CVE-2013-1569, CVE-2013-2383, CVE-2013-2384, and CVE-2013-2419. * CVE-2014-6585: out-of-bounds read. * CVE-2014-6591: more out-of-bounds reads. * CVE-2014-7923: memory corruption in regular expression comparison. * CVE-2014-7926: memory corruption in regular expression comparison. * CVE-2014-7940: uninitialized memory in i18n/icol.cpp. * CVE-2014-9654: more regular expression handling issues. -- Michael Gilbert <[email protected]> Sun, 15 Mar 2015 01:30:40 +0000