-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 03 Jul 2025 16:06:10 +0800 Source: jpeg-xl Binary: libjpegxl-java libjpegxl-java-dbgsym libjxl-dev libjxl-devtools libjxl-devtools-dbgsym libjxl-tools libjxl-tools-dbgsym libjxl0.7 libjxl0.7-dbgsym Architecture: mipsel Version: 0.7.0-10+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Aron Xu Description: libjpegxl-java - JPEG XL Image Coding System - "JXL" (java bindings) libjxl-dev - JPEG XL Image Coding System - "JXL" (development files) libjxl-devtools - JPEG XL Image Coding System - "JXL" (dev command line utility) libjxl-tools - JPEG XL Image Coding System - "JXL" (command line utility) libjxl0.7 - JPEG XL Image Coding System - "JXL" (shared libraries) Closes: 1034722 1055306 1088818 Changes: jpeg-xl (0.7.0-10+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2023-0645: out of bounds read in the exif handler (Closes: #1034722) * CVE-2023-35790: integer underflow in patch decoding can lead to a denial of service issue. (Closes: #1055306) * CVE-2024-11403: out-of-bounds write in the JPEG decoder when doing recompression. (Closes: #1088818) * CVE-2024-11498: stack buffer overflow in modular trees (Closes: #1088818) Checksums-Sha1: 6a1784ca2d664ca8cf3f47db192a816f7b7779f6 14212 jpeg-xl_0.7.0-10+deb12u1_mipsel-buildd.buildinfo 0579428a5ed99dd9b4bc302deda6bc3227ac3474 7126704 libjpegxl-java-dbgsym_0.7.0-10+deb12u1_mipsel.deb 7f5d23de7d96e93a601d8df40bc0075080fc87be 345616 libjpegxl-java_0.7.0-10+deb12u1_mipsel.deb 4cacb34ac989c2fd3871d2f03b69b4d85f260075 49632 libjxl-dev_0.7.0-10+deb12u1_mipsel.deb d5e3a340344237392abad76440744aea61f55cf9 204441168 libjxl-devtools-dbgsym_0.7.0-10+deb12u1_mipsel.deb 05f7e30b63ade6041be00d6c985f88ee8c11f7fd 2260772 libjxl-devtools_0.7.0-10+deb12u1_mipsel.deb 7a3b1c3214d8152acf96b5543c1ba51de3460907 20051996 libjxl-tools-dbgsym_0.7.0-10+deb12u1_mipsel.deb 8c84681a7b6380cadc26c65cd2cf06fbb3540801 797540 libjxl-tools_0.7.0-10+deb12u1_mipsel.deb 019d0f84b90efad0d11ee3749ad27ed17c124e5e 16343096 libjxl0.7-dbgsym_0.7.0-10+deb12u1_mipsel.deb c542eb12fb21338064ff84c7d306c10499e54e5d 723156 libjxl0.7_0.7.0-10+deb12u1_mipsel.deb Checksums-Sha256: 3c907e230276728b8ed9c7be626c52fb1376322fc0274d42cd997cbfd5f3b9ea 14212 jpeg-xl_0.7.0-10+deb12u1_mipsel-buildd.buildinfo b42c1149604f17729017808fcaae8c588946b20dd5cdd92003687969d1469280 7126704 libjpegxl-java-dbgsym_0.7.0-10+deb12u1_mipsel.deb 2943ac36320aab6f6481393c99f423c42073cc4c94f7b741994cef7928596e36 345616 libjpegxl-java_0.7.0-10+deb12u1_mipsel.deb cccea8132e0b3f5272bf8eb3c5ffad13f8d86a11e7ecd65420db7390df7b11e2 49632 libjxl-dev_0.7.0-10+deb12u1_mipsel.deb 18b6c8c7e69e84a0c4893acf36be73dffdad40c673a2fd53d9a8684462008eae 204441168 libjxl-devtools-dbgsym_0.7.0-10+deb12u1_mipsel.deb f74b00f469c7d4dd810c1129c082be3dd93b7b07bb474be8bd8e6dfc6d96bdd4 2260772 libjxl-devtools_0.7.0-10+deb12u1_mipsel.deb 5f47298e14ff78e0d296918ce734bc54a713e4f840d2d41e5c0bb8f2c157b6cf 20051996 libjxl-tools-dbgsym_0.7.0-10+deb12u1_mipsel.deb 37ca77b5cc62228bc57683e507c035531b8cdd35c2fafc8e3e432bd1009ebb00 797540 libjxl-tools_0.7.0-10+deb12u1_mipsel.deb f98b068f1991eea12a1a23d18d09ea3873ab44a227055cd61cce490dc2c8eeb1 16343096 libjxl0.7-dbgsym_0.7.0-10+deb12u1_mipsel.deb 6ec3a29003014fe0cbc308aaaee2a207153aa65d656e8399863ea0fda56b3ecf 723156 libjxl0.7_0.7.0-10+deb12u1_mipsel.deb Files: a4caaea2b93fc0c4e34ed8a6d3a1785c 14212 graphics optional jpeg-xl_0.7.0-10+deb12u1_mipsel-buildd.buildinfo 6d235939b05b363923b1149cfefe0245 7126704 debug optional libjpegxl-java-dbgsym_0.7.0-10+deb12u1_mipsel.deb 56bd95a98c7e5d8a9b784e15563679c1 345616 java optional libjpegxl-java_0.7.0-10+deb12u1_mipsel.deb 785079c9abb0ce875d9c96ca0385261b 49632 libdevel optional libjxl-dev_0.7.0-10+deb12u1_mipsel.deb 2ba65a795e16fa628125040fe89dc7bb 204441168 debug optional libjxl-devtools-dbgsym_0.7.0-10+deb12u1_mipsel.deb 2bc434bbecf52dc1cb26d9df96c8e27e 2260772 utils optional libjxl-devtools_0.7.0-10+deb12u1_mipsel.deb 2635a555cf6a2ffb221254bde36d6d42 20051996 debug optional libjxl-tools-dbgsym_0.7.0-10+deb12u1_mipsel.deb 7b0ddd5c9d6dfacede84a9ad8acbf1e4 797540 utils optional libjxl-tools_0.7.0-10+deb12u1_mipsel.deb e6459bab4cb3301d248dba20824a7721 16343096 debug optional libjxl0.7-dbgsym_0.7.0-10+deb12u1_mipsel.deb 3852b54891fd1eaacbf3e31118abcd53 723156 libs optional libjxl0.7_0.7.0-10+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYLhEzFkGpb3yYRVHmlVdU6AM9BUFAmhmYdgACgkQmlVdU6AM 9BXUZRAAqX5Jo2BpzHpTyeq7+I3m21oKaQA8NOTpPn3Grt84XcNh4l8bSUW0PnjU Otl5LZZmC/Fd22Aqg5Q1r9tDAKOZddp/dqo7NhEd6iuFT1qxf7eBKz54ra8BomN7 lY+nqkx9Bzm3u7MmuW9TOa1xwM2royMhRqOnM4r4bA50yp0AHX+BVMLH3wdfJU6g tufJNIlL9jdMGF9N13ZwYhwpETMXU/4imFumfSx357DSPlSV6w8APgniqo+lXYb4 pw43xNKWtkCQTVQmYeXBgEEzjS3AZ3knsIIPc7F1687knGrmvEykGi/uBTTKD3BY 78zO4bSecWveLWlri0sTR1JhkkSETwwRTsYYxJUI13X7yCHy8rpogqmBVpNabluq t9WFxEOD9ivcOkNOGBpvZ4ETs/lmznPRd4dNJGgsa4Voupqo3PTyayg67ZM5dkCc lmbj76Utq61hNNaGd2Gyrxxazl64O2bkq0z13IFS9HoBW4ljmLXR1QwfkFtyUouM of1nsAYzIJY+0mHRK3hoIAi6QSwpDS+hMrt/vd+WUj0YBZZ1TsbQU4AOJewdj4j9 otpSclSpQ2DiUi1ExX8wnJMqBIKvElM2+dpfGdnKp27Rp26g0zMrDKXPPsBquhXw 6tUIPCvFKZ65iK46ieq4w9b6kk4kGqAgDojnM5529vB8Ov4pagI= =myqA -----END PGP SIGNATURE-----