-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Dec 2025 11:15:39 +0100 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16 libpng16-16-dbgsym libpng16-16-udeb Architecture: ppc64el Version: 1.6.39-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16 - PNG library - runtime (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) Closes: 1121216 1121217 1121218 1121219 1121877 Changes: libpng1.6 (1.6.39-2+deb12u1) bookworm-security; urgency=high . * Security upload targeting boowkorm. * Backport fixes for: - CVE-2025-64505 - Heap buffer over-read (Closes: #1121219) - CVE-2025-64506 - Heap buffer over-read (Closes: #1121218) - CVE-2025-64720 - Heap buffer overflow (Closes: #1121217) - CVE-2025-65018 - Heap buffer overflow (Closes: #1121216) - CVE-2025-66293 - Out-of-bounds read (Closes: #1121877) * Set gbp.conf for bookworm and enable salsa CI Checksums-Sha1: 1a5d3abddba7f31536f3bd761a3653c46ce1909d 374656 libpng-dev_1.6.39-2+deb12u1_ppc64el.deb a1002fe28ffc86f40cb029c385001023e3b5ae99 50628 libpng-tools-dbgsym_1.6.39-2+deb12u1_ppc64el.deb dcf0bd585f2a9f0ad38a26fcfe18af4dacb9a390 128328 libpng-tools_1.6.39-2+deb12u1_ppc64el.deb 79a80dd04917b1cffbcf42b97ea3a623c240e872 7555 libpng1.6_1.6.39-2+deb12u1_ppc64el-buildd.buildinfo 032bd898386348d7fda306d3b9e7394176e1d17a 260508 libpng16-16-dbgsym_1.6.39-2+deb12u1_ppc64el.deb b3f834e62e55eda756df59519ebef7ace745669d 107172 libpng16-16-udeb_1.6.39-2+deb12u1_ppc64el.udeb cd7dab70858e107764bfc84ef84ecf2ddd425d93 289920 libpng16-16_1.6.39-2+deb12u1_ppc64el.deb Checksums-Sha256: 1fbd36066b9ddfefe39fc9fd8121edac3c8ab28227cfc5d05903a62746e97f58 374656 libpng-dev_1.6.39-2+deb12u1_ppc64el.deb 64432d4bb4a77cd73eb0f72b6a773f6f208f20ad0ec3297ab30326bfdd893246 50628 libpng-tools-dbgsym_1.6.39-2+deb12u1_ppc64el.deb 1d13933c7e398d7e6d3e86de330e7c0e666b50bd7dff19bf341dfdd6e2b0a59c 128328 libpng-tools_1.6.39-2+deb12u1_ppc64el.deb d778019596360c6f400f19ba8c4b98d591dab5fe6d377fd05213243856558fc8 7555 libpng1.6_1.6.39-2+deb12u1_ppc64el-buildd.buildinfo af9bc0ae0b13ee4a310a589846e7e25fc091ff56646ccdeb5835f43a32771354 260508 libpng16-16-dbgsym_1.6.39-2+deb12u1_ppc64el.deb f1f5b9d3c71a23989f685f30a2a2f3e83b784209f81c5dd5f86c9df021c172d7 107172 libpng16-16-udeb_1.6.39-2+deb12u1_ppc64el.udeb d8d216b5279fda884f1b23df829db6db2b6efba0bea5ec725fa8dcf0d055214f 289920 libpng16-16_1.6.39-2+deb12u1_ppc64el.deb Files: 85567f068fd1f92b9b9edbfd5dd34378 374656 libdevel optional libpng-dev_1.6.39-2+deb12u1_ppc64el.deb cb1c8b4d8d09a654d1338d96d75221da 50628 debug optional libpng-tools-dbgsym_1.6.39-2+deb12u1_ppc64el.deb 13fc233d2f5ea3a464f43a80ce2904d3 128328 libdevel optional libpng-tools_1.6.39-2+deb12u1_ppc64el.deb 33bcea58fe02f41120b4f791e29b5402 7555 libs optional libpng1.6_1.6.39-2+deb12u1_ppc64el-buildd.buildinfo 76ea06eb731ecdb041346d0a21f781b3 260508 debug optional libpng16-16-dbgsym_1.6.39-2+deb12u1_ppc64el.deb 71c79608e3dad798e3bc6c1906ee83d1 107172 debian-installer optional libpng16-16-udeb_1.6.39-2+deb12u1_ppc64el.udeb 1ae1db2f1d2a71aa595a49bcf2ec0d72 289920 libs optional libpng16-16_1.6.39-2+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEcgNjDiyOcnJRaE/rxc5dwsVCzVkFAmlY/lkACgkQxc5dwsVC zVkYThAAoAmhgBdj0+lcM1LLezxHNwBW1pSrY/dWYqvwZK2cxHueuK3gp39nS28I hKdJzpEPN7bsGo5tyIyhT4euQRSIA6JRtKjwRdaJ4NqLhuc0BuRk4xZGKtZIijIN 7d4NheugcJKoSx2NKe+diCDtUvILPkR5rGCZhqD/KOs8Qi58WfwLKjEMcjeVg/xb NZpDN2c2BsXJEeH28ZijPpGmZVGvz6sIUSL7/nXTUek34PbApR4cQ2QVFL8s/mR9 8Zqy+8Dy6yLeURGX16UYKpUlzCCpge7Q4ZHU/rBKYII0RiPtTQNBOttix65776qX FVjPBejjaIDD/VjgO7MHlQb2xrO1mW0Lc9teKBEsSDZkxgKVkfFW2M45hVGQTGjX iRwphM7ptKc3TDoTCNjiBNbhxJc6Y5Kn7SC2MQvqFutglbTu7ZUa63tzgUt8trb0 0/skbzPGF4k9Li2G/dM4PXkTMaVmcM7Dv9xFdB2RE0hg1MW81a2F7eHCyyjocajO y5V/o7AWEx3CbzWXzTDdZExOVzflMPzXArbbCkbHA9exxOfeQ9A9ZMT9iseC5vH/ ccd6SBqso7m0FCdI8CnWnla5YOjLu5Se6QrvwoitslLs9XE4l8gJJ2AOdmAPIzF+ PfdU+uF+WIxfq7DSHSY8oc2hb9ZDWebi6hL3bWIxCBJrbcoEdKs= =fwTf -----END PGP SIGNATURE-----