-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 08 Feb 2024 12:31:43 +0100 Source: libgit2 Binary: libgit2-1.5 libgit2-1.5-dbgsym libgit2-dev Architecture: i386 Version: 1.5.1+ds-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Timo Röhling Description: libgit2-1.5 - low-level Git library libgit2-dev - low-level Git library (development files) Closes: 1063415 1063416 Changes: libgit2 (1.5.1+ds-1+deb12u1) bookworm-security; urgency=high . * Team upload. * Fix CVE-2024-24575: Denial of service attack in git_revparse_single (Closes: #1063415) * Fix CVE-2024-24577: Use-after-free in git_index_add (Closes: #1063416) Checksums-Sha1: 8f4316558014c1475a96a547c5c68655b4c3384b 1420304 libgit2-1.5-dbgsym_1.5.1+ds-1+deb12u1_i386.deb b60941f8ca5fe9acbfba193bf296c334ed3516fe 551268 libgit2-1.5_1.5.1+ds-1+deb12u1_i386.deb 9a82bfef1cce0883e98edfb3cd0158bfb885d407 849696 libgit2-dev_1.5.1+ds-1+deb12u1_i386.deb 3b1984a180548698a8caad2bdacf764481071d78 7955 libgit2_1.5.1+ds-1+deb12u1_i386-buildd.buildinfo Checksums-Sha256: 021aeb685e32159c3cc2c6681168a46a5946912f5532d6c499aeb63e1c8f8a90 1420304 libgit2-1.5-dbgsym_1.5.1+ds-1+deb12u1_i386.deb 3687703ef36b5b75ae2901eb8c4f04e90b1cb463c6dec58b4064b14ebeb7acf2 551268 libgit2-1.5_1.5.1+ds-1+deb12u1_i386.deb 5498116e7c87172fd0328684d44b44d3227379423b23ed7781be41c8ab3b9673 849696 libgit2-dev_1.5.1+ds-1+deb12u1_i386.deb e37d2d89d53eba59a8b0624ab330125f467f7c27a63c47be1e00c4ea868678f9 7955 libgit2_1.5.1+ds-1+deb12u1_i386-buildd.buildinfo Files: bca7fd40aa1fab446c2aeb927f084053 1420304 debug optional libgit2-1.5-dbgsym_1.5.1+ds-1+deb12u1_i386.deb 9e2328ae4299979ed9373f7a266550c4 551268 libs optional libgit2-1.5_1.5.1+ds-1+deb12u1_i386.deb 21dc62569a3314551116b9aeb4494262 849696 libdevel optional libgit2-dev_1.5.1+ds-1+deb12u1_i386.deb 6fbce338b2c921cedc0056a79c480e85 7955 libs optional libgit2_1.5.1+ds-1+deb12u1_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEqYm4ZPyuLwhx8Meo2VckltclZ4AFAmXFOB0ACgkQ2Vckltcl Z4AZ2A/8CDDX08JMw+f/ow9fWIHp98DfbdC5vB4b172UhRllzY+xEPwvp3NuTbRh I7PbZ9O2z4es5b+/BfxdumfNJN1L1b6x35zbZ+cSIW73FlP3nlKP1YdPmlQlgYqC nCBkdX9HRLw4tL43Cfep8cPm8YMNjOfOfUldXeIcrXGtHniAPwV2XEbZvKZ4mHIQ 7UYTP2GmS9sKjqJUReqsQtJfa4ouVz4oPnISMhGk4CwSY1747dpygn7m1nOoL4xv wMqTsefTVZEPpKp5r5YUoMpbXIAhLEfCCPO750iKmg0uOV03gGsKlEjApVE8oCZi +nlA1vCx/kSUuEtRx74jYCY9AjQYXd4IuMuBuZ3JAAkcVuDsBQEgfGFr88W2+qRU DKznD+7vDx3C2Uf9bgecebWudTtUHRGWfVdBnzCb5hgzTdQBuAr6cd78BvuFSJ2M L/OgCT75/a2hnFamJquOGUDEpndm8ExXP9lyH04tMbKFCT6D2bguhVXTnocaG2Bp 3YKEsSlWY+jxLaJIObLH2UOSRBPLpA7v9kcgSHdfZGMa2ZVb/rkRWoRXe9RiLngb P2IHAv1040LYlFJL5PEe+fPoAvGs8T9wseAZ9Et8wRqbSTUbZ7hOfamLaJlSKmU0 Or8VKgBZI4Q9RzbBhH61de8sj40TaqbsK8JWddiv4vo7JKfVAfc= =0sG0 -----END PGP SIGNATURE-----