-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 23 Jun 2024 18:25:00 +0200 Source: indent Binary: indent indent-dbgsym Architecture: amd64 Version: 2.2.12-1+deb11u1 Distribution: bullseye Urgency: low Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Santiago Vila Description: indent - C language source code formatting program Closes: 1036851 1049366 1061543 Changes: indent (2.2.12-1+deb11u1) bullseye; urgency=low . * Restore the ROUND_UP macro and adjust the initial buffer size. Patch from the author, backported from 2.2.13. Fix memory handling problem. Closes: #1036851. * Apply two patches by Petr Písař . - Fix an out-of-buffer read in search_brace()/lexi() on an condition without parentheses followed with an overlong comment. - Fix a heap buffer overwrite in search_brace(). Closes: #1049366. This one is CVE-2023-40305. * Fix a heap buffer underread in set_buf_break(). Closes: #1061543. Patch by Petr Písař . This is CVE-2024-0911. Checksums-Sha1: 8585ed3b4320ee9adafd85d0a06cc3a43da6c499 82564 indent-dbgsym_2.2.12-1+deb11u1_amd64.deb 03dcb9755447f9564cebfca5983180ffecd11667 6370 indent_2.2.12-1+deb11u1_amd64-buildd.buildinfo e3114143ce12a97fea0a822c3ae4b4fa2a0dd575 127664 indent_2.2.12-1+deb11u1_amd64.deb Checksums-Sha256: 57c0c583d05882e15510721b1866598fa2d15dd1f5dae51f6e28a7428b58b754 82564 indent-dbgsym_2.2.12-1+deb11u1_amd64.deb bc186a0ae41f183226aeea8d456d61618723d88310903f9524266ea88ab74a28 6370 indent_2.2.12-1+deb11u1_amd64-buildd.buildinfo 3537db19bc4812f6d5d6ff019d21e97fe9dc224c254647dbe2b721555f09b88e 127664 indent_2.2.12-1+deb11u1_amd64.deb Files: 3709806d07831b47bf8e2e25bef96dc1 82564 debug optional indent-dbgsym_2.2.12-1+deb11u1_amd64.deb adab607bf161728fd0f0c94520d27b6a 6370 devel optional indent_2.2.12-1+deb11u1_amd64-buildd.buildinfo 60dad382828cec4e757a9b5b02827e0d 127664 devel optional indent_2.2.12-1+deb11u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvy6d65NNYPbL6IQIEQ1nooK/IAQFAmaAeWwACgkQEQ1nooK/ IARjgg//bnz3lf2kF6ETblfWzLhw/UxPuazQmziYjuC5/LbEn9K/6wUKOCRsnLDk W/y6eUnC6OuPaXDZu/uEIJhQMuhJpwe+mEOPps3vBWJLOFbLO62U4VVQ4DcWqYnr V+Bdn7mC0pIZZaMV3g0K0tviXZJG7mbS/PXkQN3jKznmJC45qS1ssvQNia2MmL4h nMKOtFu1/D5dbKbVuMcqbDiaC4qM/XUP5o9yblzSbVrWUAf6aAgqU1wKUdo+GOqU IdsOcnUMulNW9Wk+ggju168kIZqu685xZlIzSs4Us6P5S2MZG9jAjiEiU5witETD qBze0lB4yjF+/EFVyYkNnwxTQc0ebfpd9yr20hBtWBu6GG1b0PVGkSgtrhWCJ1M1 Kbmg+pPLkRiiPmEPydDprBQAFM1y4Fuuk0ShhuXTD1kGhlQyhoHXFbMxd+kwTfQ1 SmEDuxS/qeo4EuqWPwzQUvToJJWIJqydLvIQEhZYALY05AulJQKqk3LOOC2aIlZd k8HjGq0Jy+xdRxeQoVlRb+CPttZkA0g59e0T384OBmAAlLGIIXQIw7w7a/kGrmHW /eXrCgjXqaNTVfLLtQYdbASiTtzeM4xd74RFxq4p0SajS/Z5RmwRYvsWBrZ07NZ9 xNnATK3o03j6cIXjBr2nkCmgHVDjFMkssxcooUAsuHkLojCCQ+M= =sy6Y -----END PGP SIGNATURE-----