-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 08 Feb 2024 12:31:43 +0100 Source: libgit2 Binary: libgit2-1.5 libgit2-1.5-dbgsym libgit2-dev Architecture: amd64 Version: 1.5.1+ds-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Timo Röhling Description: libgit2-1.5 - low-level Git library libgit2-dev - low-level Git library (development files) Closes: 1063415 1063416 Changes: libgit2 (1.5.1+ds-1+deb12u1) bookworm-security; urgency=high . * Team upload. * Fix CVE-2024-24575: Denial of service attack in git_revparse_single (Closes: #1063415) * Fix CVE-2024-24577: Use-after-free in git_index_add (Closes: #1063416) Checksums-Sha1: cf94b81de562ceee9033ee7d41bb179edad786b6 1670776 libgit2-1.5-dbgsym_1.5.1+ds-1+deb12u1_amd64.deb 06cb05688be453ec7c709a6892602b14b5fa11da 502248 libgit2-1.5_1.5.1+ds-1+deb12u1_amd64.deb a1608fc9ae6e1e6e955134206a446919c60f02ff 775832 libgit2-dev_1.5.1+ds-1+deb12u1_amd64.deb e3ef7519d05f1446f86b4a641cff22754f758acf 8002 libgit2_1.5.1+ds-1+deb12u1_amd64-buildd.buildinfo Checksums-Sha256: a8dd38744a5f1acc3c5fdfd199f667e58bef9b7b301234a13fb301814cc38fbe 1670776 libgit2-1.5-dbgsym_1.5.1+ds-1+deb12u1_amd64.deb 1fa025157c73990eb3024a4356d15d3625ea9a23dfa88bca9bca05f8a8d4b3af 502248 libgit2-1.5_1.5.1+ds-1+deb12u1_amd64.deb 880bdddeafec07a1029b442bf465b6dec3821da6786dcab24fdb646d44e42004 775832 libgit2-dev_1.5.1+ds-1+deb12u1_amd64.deb fb0e5fdb7f9c20cf2741209e5c4cf98fbfd5e4dc8786a924bbd47d58d8354967 8002 libgit2_1.5.1+ds-1+deb12u1_amd64-buildd.buildinfo Files: 41b061810cbc73650a7871a31d258993 1670776 debug optional libgit2-1.5-dbgsym_1.5.1+ds-1+deb12u1_amd64.deb 5e53189e484db7dc261567834aa4aa1f 502248 libs optional libgit2-1.5_1.5.1+ds-1+deb12u1_amd64.deb 62276f63d4abfd5d3ef2a9ac41fa0a66 775832 libdevel optional libgit2-dev_1.5.1+ds-1+deb12u1_amd64.deb a8f36848d205d36f43ab9d25c0edd1dd 8002 libs optional libgit2_1.5.1+ds-1+deb12u1_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJyRdn7p9tGRfxctAots23/koc0EFAmXFOHIACgkQots23/ko c0GmYA/+KmvvUa0RWZxJbc7SJrN3rAwJrjyPzdfICaUiC600EP6JDBe+ZYe7GZxe ZNz1Zl6Ju/JaFHbAeIaFkxpoC6rL0qVJ9HviQoXWB/yiNZYaGC/aB7/aDSakOcK8 2v3KlnOwUstY7ON22z9ljjB8jepfyUhwa+mQdFkQufgBg38MP0Q20U0OYIjmd16a ewwYL9MLvCaPD/IzPc54GPfjNlXB0KSnfK2Xws390gxzqzT5aN6CJj9n+7warb7G UAjgeG1b/pXc5Pv/n3uFs5NOuI3R+u6J0rtR/0e/f00CXkLFw/ezG6VKj0KEcUI7 IGayu5O+iwAp2t4AmQxh2tXpUAADjp8d/HNmNy7Z4SOS+Id5V0bQWZG7sVnE8sTY K25l2huFpnnkt9WZY8fs+1GcumNTXIMCK2NcEgpTbjF56SlkTBssD8OInTYP78cV ZOut1x+RkHmM0uZ7HhYnP2lcWWampV8viERCvgdKqc0cUxdC+RD9ioM2kYCkznyD YFAHqYZrdwRMrwRzphlEh3YyoSD5Wwk4atroE4HLC+LScxt76ak/cQWMjugEZFZX jjc6dd8wCmLWeoFjaeiEbCQTn/EENJHj4Ynzk/lpYOnz7dbqbANsiZhCJArbxMSm SAMl04f2pY1Oq1XO3Q300ame405m6VttXCa7Q+dsyFKRqUS40rE= =RbJM -----END PGP SIGNATURE-----