News for package icu

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 3.0 (quilt)
Source: icu
Binary: libicu48, libicu48-dbg, libicu-dev, icu-doc
Architecture: any all
Version: 4.8.1.1-12+deb7u2
Maintainer: Jay Berkenbilt <[email protected]>
Homepage: http://www.icu-project.org
Standards-Version: 3.9.3
Build-Depends: cdbs (>= 0.4.93~), debhelper (>> 9~), dpkg-dev (>= 1.16.1~), doxygen (>= 1.7.1), hardening-wrapper
Package-List: 
 icu-doc deb doc optional
 libicu-dev deb libdevel optional
 libicu48 deb libs optional
 libicu48-dbg deb debug extra
Checksums-Sha1: 
 7146ee269b39273fa98d750f73136b14f781758a 18675781 icu_4.8.1.1.orig.tar.gz
 5e6792e2a456b66fc788c7972f546719a1c6a7db 195940 icu_4.8.1.1-12+deb7u2.debian.tar.gz
Checksums-Sha256: 
 0a70491c5fdfc5a0fa7429f820da73951e07d59a268b3d8ffe052eec65820ca1 18675781 icu_4.8.1.1.orig.tar.gz
 8629b1f3a3333923f9cfb30aba2615152633d7b4e6a9b24723847175a33a9ac2 195940 icu_4.8.1.1-12+deb7u2.debian.tar.gz
Files: 
 ea93970a0275be6b42f56953cd332c17 18675781 icu_4.8.1.1.orig.tar.gz
 4a825ad16f8b2cf9ca3dd7b27d64d587 195940 icu_4.8.1.1-12+deb7u2.debian.tar.gz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQQcBAEBCgAGBQJVBO4VAAoJELjWss0C1vRzzuAf/iAjyXTAFeBTzkLtLxqdvjp8
8QK5wrkKzXtnjaKsJw+ja6OyOc0byz0hhv59QKV/+cXWCdztPcv69kT37gEtFvSo
kIO3ITCg/llxIFbSFtYa/KbCdIS+KrNDMMbe6K6S6J7mt/IM3vSaHoDxQxZ+/9NX
xBuRu/Ogsi3bN6kVdyVUcMKPwJhtUk12rU4ipUPuWDvGJ6nfYcuofovYVPegcqTs
/KOAV69HW2YerP+BqM2Pnf4O6hyQLbPFg/H/IZHJewxLJnAPyy81cCZ2fpcY4wyy
I9QP2qBTBkYnSeKWtskNQ5E5YyJUBpF9pwopvR+3KE6LXyJ1CcHcQrHtcsxAYjef
IrIIcqFo88WikJ7nJJrneBMCQnSf70uOKlctrN5GaH8yyJIzcsEl0Ktd91G0PZwD
TZ0G2nXAloTRTfCF0vU+QfYsEg11kUrhRHrSbzFUu56IqAifYE1tGyO9PIvxleFd
5XrZ18gnypCGUtcb7IGaLGW3TpG/T7faKKY7l9YuyFAveAHu6P/iwIXWu9qY3CMq
XcoQwdAtVwFcorgEn3DVLOeYsalsz3oZdVnLGIbZDogPlcVSvB1RXK2wiGz0sHwc
TJ4keb6UriZLEv7ruE309Azhv/x8PfFHAKALelwnMFDwxuTpuWW1BhvVGfHZ5aCn
R3aRQ1MUYJiq3vdWpZJfIR1/HxUVMW0GNVXYhWYwsCa6nKjZO1U2MwK2cnD1bhOR
Ml1IbfV538BKRvZE8sCEgWex/CFEim/1BBU2pGdp2RH1+iQ5Z07eJKFMB5GmurOX
d3wMoBKhCnKEy/2wKUEUtMECTogPjWx2TPgMv3geJoAAa4WKYTZFbp0nCc3nwz0s
L2gNkIrE/AS/SnEjpCSA4sBJyZc8RoGbiysepZIrlmvHujtExmD/2y0G65CCbWGr
OiH8A1V/t2XG93+3+aaX0hyH6ewgZgMdNZLTUbz55Cv1a+tQA1lR+tiB3gPRilDX
TSeSRciia54MG2RaPcaD5NfHky3NAvZWTUwN0qWSwAH6x4OJhcEs/dH5h0VcDvub
jgwM2jRYiGY88AIb4jXK9ZcHKmF5O3obmnR5oOMcQ/Kx+05vltYPIzst2xFaX9Mh
RUWPAus0iz3xpAwFMfDQ7Z6liLXglpAWMjdgGG6a0yY2fcVuM/9OSJStW1EpYVlF
cwqUOM3oqE3qTajp5U0f3I2waQq0FcjW4qYmiV/8CGXUD2SzLLtkAiwX4ajtfWA4
Jsj+FH+H2raUmYYIPk+HUktj7ZTfgt/AgUGSnKnAUc5kV3pWeoqZnYZm7/T7/xWN
lWpGqD0ZlrcIGBzgz62oeSKTyiDA/UEapyjYBytCXYsTm6Zhkkj3fxx7IWooYhE=
=QU1k
-----END PGP SIGNATURE-----

Changes:
icu (4.8.1.1-12+deb7u2) stable-security; urgency=high

  * Non-maintainer upload by the Security Team.
    - Thanks to Marc Deslauriers for many of the backports.
  * Backport of icu's new layout engine.
    - Fixes CVE-2013-1569, CVE-2013-2383, CVE-2013-2384, and CVE-2013-2419.
  * CVE-2014-6585: out-of-bounds read.
  * CVE-2014-6591: more out-of-bounds reads.
  * CVE-2014-7923: memory corruption in regular expression comparison.
  * CVE-2014-7926: memory corruption in regular expression comparison.
  * CVE-2014-7940: uninitialized memory in i18n/icol.cpp.
  * CVE-2014-9654: more regular expression handling issues.

 -- Michael Gilbert <[email protected]>  Sun, 15 Mar 2015 01:30:40 +0000