-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Dec 2025 11:10:16 +0100 Source: libpng1.6 Binary: libpng-dev libpng-tools libpng-tools-dbgsym libpng16-16-udeb libpng16-16t64 libpng16-16t64-dbgsym Architecture: i386 Version: 1.6.48-1+deb13u1 Distribution: trixie-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Tobias Frost Description: libpng-dev - PNG library - development (version 1.6) libpng-tools - PNG library - tools (version 1.6) libpng16-16-udeb - PNG library - minimal runtime library (version 1.6) (udeb) libpng16-16t64 - PNG library - runtime (version 1.6) Closes: 1121216 1121217 1121218 1121219 1121877 Changes: libpng1.6 (1.6.48-1+deb13u1) trixie-security; urgency=high . * Security upload targeting trixie. * Backport fixes for: - CVE-2025-64505 - Heap buffer over-read (Closes: #1121219) - CVE-2025-64506 - Heap buffer over-read (Closes: #1121218) - CVE-2025-64720 - Heap buffer overflow (Closes: #1121217) - CVE-2025-65018 - Heap buffer overflow (Closes: #1121216) - CVE-2025-66293 - Out-of-bounds read (Closes: #1121877) * Set gbp.conf for trixie and enable salsa CI Checksums-Sha1: 16ad2ec182679e82419940d15f7bad171e3eff35 373684 libpng-dev_1.6.48-1+deb13u1_i386.deb 952735242f901a949eabd62add9a8af2d64ca395 49040 libpng-tools-dbgsym_1.6.48-1+deb13u1_i386.deb 8941e36230850e66b2a3d6231e3361ba28a452da 130884 libpng-tools_1.6.48-1+deb13u1_i386.deb fcb6449c235129f7c4493589423894dbad99f4b7 8003 libpng1.6_1.6.48-1+deb13u1_i386-buildd.buildinfo ceeeb8ba5713cea83a0e52c9e0cd6677869ce0a5 101924 libpng16-16-udeb_1.6.48-1+deb13u1_i386.udeb 4c05f54e12d5209c18ae20e4443415d4f6c5f365 216996 libpng16-16t64-dbgsym_1.6.48-1+deb13u1_i386.deb bc08ea8cfa25b87c392eda6fb749aaf514716cd1 289508 libpng16-16t64_1.6.48-1+deb13u1_i386.deb Checksums-Sha256: eabd03aaaca9f09e5461ec890d6896f43f19f70f463da88083759cb094f4b922 373684 libpng-dev_1.6.48-1+deb13u1_i386.deb db71312811634aec1b92d13d9bdc380f51a823f596de4e02355524dd7bc6005f 49040 libpng-tools-dbgsym_1.6.48-1+deb13u1_i386.deb 547c1222757c6a30bbcf353f320bea8404337253ca61c5fcaf0401c8efaf769a 130884 libpng-tools_1.6.48-1+deb13u1_i386.deb e55f4636d104f5092bed769aa9d95d5b439c6b866ed10d094b7260c0099b3cdf 8003 libpng1.6_1.6.48-1+deb13u1_i386-buildd.buildinfo baa99836fc0cdce56d1daafc834cd0789a48e8cc1ade93686d26b9555c31653b 101924 libpng16-16-udeb_1.6.48-1+deb13u1_i386.udeb e731db62249095e4c8e413124fbd26359486b88c28935b3376be66034025c891 216996 libpng16-16t64-dbgsym_1.6.48-1+deb13u1_i386.deb 6e7a230a42ceea7ba8549cf6c3e665cf0e5cf6ba9386f48bc74196d90873c349 289508 libpng16-16t64_1.6.48-1+deb13u1_i386.deb Files: b9b2612d20d2a017f60564f96bf384bc 373684 libdevel optional libpng-dev_1.6.48-1+deb13u1_i386.deb eabcc8b4895ef3dc7961a93e6466bc6d 49040 debug optional libpng-tools-dbgsym_1.6.48-1+deb13u1_i386.deb c7f54968c4f3d5a9924e32412c1ea00b 130884 libdevel optional libpng-tools_1.6.48-1+deb13u1_i386.deb b1e41197205265335629bb576a075861 8003 libs optional libpng1.6_1.6.48-1+deb13u1_i386-buildd.buildinfo ed1c47f3d5dd261be7594ebb67d31876 101924 debian-installer optional libpng16-16-udeb_1.6.48-1+deb13u1_i386.udeb 1b2dee754d4be2892333026e62bb9e6a 216996 debug optional libpng16-16t64-dbgsym_1.6.48-1+deb13u1_i386.deb 05cddd29cdd87d43a4c8f605ea0b663d 289508 libs optional libpng16-16t64_1.6.48-1+deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEv2qEY4xQXyY/2dWIvGw9w6VrLCcFAmk0R4gACgkQvGw9w6Vr LCeW1g//X5XXyfaVxbxuKroaXjUMHRDZXIyaeXPpQ4IcqJgSvnGw7+67jrLto9ef 4/Ccgha4ZORDndwDE+sdYASWHHtNt4d/rHHNz/FzOXSTw/G5I0FSUZnx1AcKo2E1 LgfNNcFDaxxezIl+Emrfs4He7FoCd2Xc8md5gwuv5dwxYc0h+SSh6Lknt+8UKeqg IrGZRiHlPHGl0jOA75yd39O1dgDcCbGDbQm5BGbbd0Ua1pO5s6/TF2RqGXJKBUKL casw79aB+hub0fHQwOGJq9YPyHREQnwxv8zfQfRg0FP1bWS4hFjJ+3g6k49pIhCH lZNr+hZST6jNTmQhGDxr7JP2wifezizxWlxEz/0xdW2WWx7kFAYPvhQXZJQu1ih4 J6Au3lVMIqNgTOUlzZ3PIUbDAlvXEh3E0cyeJBeTDouNDmGAItYGAo6byvfcfQpk Qyt1byrWpergRY5hYbkwA/pMVHdfOyXkw78wPGITlU8qJiPK1NVFLBpKvh+xgIo3 N/A0zQdzO9dZgwYVvffbHV/PJGUgxmCRVVDRN/OTNajYFeuuxbJ7VNl/xWQ0ETRG iQEsv5Rn46WAQEnF7pwGRt35T4Ns1n0Ba1kSEs9JZTiTufIsDje8pECLjGf8gsv/ PPLqAc3SmclfjZT01rcwruGf9DVv9UwhpCIozKQj7Wl300cVBVg= =J3/5 -----END PGP SIGNATURE-----