-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Dec 2025 11:10:16 +0100 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16-udeb libpng16-16t64 libpng16-16t64-dbgsym Architecture: riscv64 Version: 1.6.48-1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: riscv64 Build Daemon (rv-manda-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) libpng16-16t64 - PNG library - runtime (version 1.6) Closes: 1121216 1121217 1121218 1121219 1121877 Changes: libpng1.6 (1.6.48-1+deb13u1) trixie-security; urgency=high . * Security upload targeting trixie. * Backport fixes for: - CVE-2025-64505 - Heap buffer over-read (Closes: #1121219) - CVE-2025-64506 - Heap buffer over-read (Closes: #1121218) - CVE-2025-64720 - Heap buffer overflow (Closes: #1121217) - CVE-2025-65018 - Heap buffer overflow (Closes: #1121216) - CVE-2025-66293 - Out-of-bounds read (Closes: #1121877) * Set gbp.conf for trixie and enable salsa CI Checksums-Sha1: e5d19534bc7d1e62f4930ab857414f7add60ccfd 511000 libpng-dev_1.6.48-1+deb13u1_riscv64.deb 3e6008ad81649c57378e562ebbecda19f6f01666 48372 libpng-tools-dbgsym_1.6.48-1+deb13u1_riscv64.deb 67fa983fed63e4fd1c493338e5f8de0e7d10d618 130392 libpng-tools_1.6.48-1+deb13u1_riscv64.deb 7563d4ee216f87d02e187446934dfc4d06665851 8079 libpng1.6_1.6.48-1+deb13u1_riscv64-buildd.buildinfo 4003ed278198085e00422223c23c6f01c86a98c6 98772 libpng16-16-udeb_1.6.48-1+deb13u1_riscv64.udeb b345015f77874ea9b9db05bcaf8832ba245a3003 239224 libpng16-16t64-dbgsym_1.6.48-1+deb13u1_riscv64.deb efc4fdc36935a3c1486ec8472ca99d0178f5c42f 286156 libpng16-16t64_1.6.48-1+deb13u1_riscv64.deb Checksums-Sha256: 5bff1114b7b1d8cceaf9cdae6d7e74f044a5933c776c9324c4873a2326ee20c8 511000 libpng-dev_1.6.48-1+deb13u1_riscv64.deb 8cf3ee20d30247835664bd0ae75d6805e02290e9dcd7f5c2329beab12d7d05de 48372 libpng-tools-dbgsym_1.6.48-1+deb13u1_riscv64.deb a742c183e5ff4f89a2ab99ea33a87d31403096d90ec3a009877f0f5f6631282c 130392 libpng-tools_1.6.48-1+deb13u1_riscv64.deb f7714993876dbc05ef5a5e0c5263003c0b35f1312d3de50d890f3f70d7177a5e 8079 libpng1.6_1.6.48-1+deb13u1_riscv64-buildd.buildinfo 36fe71a56edcbe64beacaaacc6ea6b7e8f30e5e336413999e19081b18871d389 98772 libpng16-16-udeb_1.6.48-1+deb13u1_riscv64.udeb ea004a1e324d494ee548040091af15be5417061fda60e868d4b6258d71912fde 239224 libpng16-16t64-dbgsym_1.6.48-1+deb13u1_riscv64.deb 262cb5a1859323c813ef5e34538af47293e71b7dfadaab97b2a590ca3ec3b190 286156 libpng16-16t64_1.6.48-1+deb13u1_riscv64.deb Files: c3c1562f22642de536786ae746fdb845 511000 libdevel optional libpng-dev_1.6.48-1+deb13u1_riscv64.deb 0d5cd4e4b8f968da66b18c1796a64efe 48372 debug optional libpng-tools-dbgsym_1.6.48-1+deb13u1_riscv64.deb e11b5b8f2eb5b76f202d715e2a5b78a5 130392 libdevel optional libpng-tools_1.6.48-1+deb13u1_riscv64.deb 1f80492b344dee8dea72046d98334312 8079 libs optional libpng1.6_1.6.48-1+deb13u1_riscv64-buildd.buildinfo 60721d42066f507ff8d6407723eede67 98772 debian-installer optional libpng16-16-udeb_1.6.48-1+deb13u1_riscv64.udeb 7d0bea4f8c2ac768f40daca204540641 239224 debug optional libpng16-16t64-dbgsym_1.6.48-1+deb13u1_riscv64.deb de814f600f0664f054b90d83f4fad3b4 286156 libs optional libpng16-16t64_1.6.48-1+deb13u1_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwN+C+Bc8deN4UliX50ghctvtZFQFAmk0TPEACgkQ50ghctvt ZFRZHxAAu87A2vm5hUc+JD/J03Gz1rlj41v4QXE1HsOIciAMqGHmOx/7EILGFc5t KopSzzRa9mN9P+PNYOqssc830GuDEJaupJQ24teD4v+IRmILQct55dFqJvcft71t v4Ua6G70Df9zTRo0zeQpt4FbZ09MN4KuUKRsL2UHONmqHIgNdYg743DpdbjNWDY2 iEpZXjDaFgAaqiYFYv/pfcGHUAJ58JrTJLwZ1oCHejCIrop5GGzrhWtpoIWfQYrT EuFQgWe0NEbnJanO1v9zHDXWneEsxQAJJCfn6/NsKEZqyjfa39IY7uizSbYM3bha n32XGv3j+O1DFDLUrFo5frjdTTzYPd1WkFnBJ6Rr18VS9D2t1Bf1RFrd+u58wU7a p4Kkc4VwF/RpfvrWu2ahte0r8y8GsoklLSUak8qnf5xV3+1ItdfHFBSlcCHnAaaI 5XnuczhNodUFdFvjVFGcLSxRdW6P4qv3sNnH4sxzammT+GIumzOx+o4w1CKW7uKi u6BtvB3YPnu2k9yg63/MCdmBuOPBuKl1Liy6Hmg1FVYB9tZ9pobqG7hkGnFzGrRo q42eUOlO2OPm2qejJRd9kzWht+E9JlkXZXtDLza/FCE/w6MnAdpoclgN2IX94KYz sB9+brYjn18EQ/Pjl2ItkApPvbbIfW67w6TC3b5g9R1o/OVpm2w= =yhgE -----END PGP SIGNATURE-----