-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Nov 2025 12:05:10 +0100 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: armhf Version: 0.1+dfsg-4.2+deb13u1 Distribution: trixie Urgency: medium Maintainer: arm Build Daemon (arm-ubc-05) Changed-By: Thorsten Alteholz Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1109341 Changes: rlottie (0.1+dfsg-4.2+deb13u1) trixie; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2025-0634 (Closes: #1109341) CVE-2025-53074 CVE-2025-53075 Most patches to fix these issues are already part of: Fix-crash-on-invalid-data.patch The remaining boundary check is left in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch For the sake of completeness, the whole upstream patch for these CVEs is added in: CVE-2025-0634-CVE-2025-53074-CVE-2025-53075.patch.org Checksums-Sha1: 7a712464104b1ac6afdf01510230ee1ab2c96db1 20996 librlottie-dev_0.1+dfsg-4.2+deb13u1_armhf.deb 37fb3f138ae12304e508f43b3f2a0730a867fa13 2033064 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_armhf.deb d97aa69ae42d32b1afc036458f87e1249600a3bf 110192 librlottie0-1_0.1+dfsg-4.2+deb13u1_armhf.deb b3ad2ca8ce580ab68107504e4d2f241b7433d8fd 7239 rlottie_0.1+dfsg-4.2+deb13u1_armhf-buildd.buildinfo Checksums-Sha256: 891339c4ecafe82016de859f544fd23f6391c53db24ec8cc15896ad690dac220 20996 librlottie-dev_0.1+dfsg-4.2+deb13u1_armhf.deb 670a6213ce5f18f0079528335d0d1387e632694982f40b3c641b805999ce75ce 2033064 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_armhf.deb 10210d69c6c02965c56cbeef692c4433629511720995757e0558fe7868fe0776 110192 librlottie0-1_0.1+dfsg-4.2+deb13u1_armhf.deb d6e3bd95274328a64ee1a17000287637b998db7e47614f1b1aa550784910ef4d 7239 rlottie_0.1+dfsg-4.2+deb13u1_armhf-buildd.buildinfo Files: 5fe07c2e1550c85ac28e50ae6ced44c3 20996 libdevel optional librlottie-dev_0.1+dfsg-4.2+deb13u1_armhf.deb 5493d3ef2c7bdaf3a4657798ed63d4b3 2033064 debug optional librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u1_armhf.deb db498ac3325d42f0c52d5c8a91b23d62 110192 libs optional librlottie0-1_0.1+dfsg-4.2+deb13u1_armhf.deb e76874078d5391f65c04cb5d2ee85f75 7239 libs optional rlottie_0.1+dfsg-4.2+deb13u1_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiIG3Q3DxwDgRKKeyLRECdjCZQkcFAmlG1JsACgkQLRECdjCZ QkdttQ/5AdWzCqQwLo4WqAc/jfHsmoXeETNeKgP/WpkkWqQKv5+EFoPeUZH4crME ION3H2/6+GEFuYrcYeWigOhPRXJdF9R4fMn4RsfQhfu136L7EaJ0IMc0IQuwyXC9 pnBEg0AiSRC3CEf5AHOP00uzJr8Vlq/Ci52U4zbPmz+HHuHkSWkgluWzJgZaN4e7 cSVf51Nco5nl2hYTwt8zRvveU7JEoIyfSuzPlmXWyolI5xztZVkfAg7oaT7LlDCm vU0isLT5p2zhVmRgg/k8isMx1b8XQuMp5wPwuSuZxBGJNaBoM49b4SjTtAuydW6z 7ahUl3yUDbIMkT9IOgvhVQ7GxW1Qvsf5zDsQHKknMzV45hozhjJIWMgeK60DtszD nUUPZmrxyMj4G/Pq3bpyEw9Vubvb3IQ2hGx+rRwNiAOPoCSOzfvpV1bIIvozZSlw EICvlYSZ3Ml65rkggluC+xrI3yK+R6cFyEayHpSsWQp3m3F/NyuaJ6wC2fufZhY+ HGiRY957YPSTEzptXA1wFqlNXtXj71PAw2A28iDdMnCqBWcPjzQwY7sMBrISLiVC UBIEPNrTTJtwMtWx00G1RZmT1kvNS9SO0HTiuRkmFeUashuiSNnyQQTWGNomQMEE TVlWaSlax8hM5iY1AbkJauCi70XSSzPZQcBQO/qFSuKSuC2JRTo= =2lRT -----END PGP SIGNATURE-----