-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 03 Jul 2026 14:07:04 +0300 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: amd64 Version: 0.1+dfsg-4+deb12u2 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Nicholas Guriev Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1138919 1138920 1139179 Changes: rlottie (0.1+dfsg-4+deb12u2) bookworm; urgency=medium . * Fix off-by-one error in Fortify-FreeType-raster.patch. * Add Fixed-vpath-potential-issue.patch to fix CVE-2026-47319. (Closes: #1138919) * Add Limit-recursion-in-LOTLayerItem.patch to fix CVE-2026-47320. (Closes: #1138920) * New Fixed-signed-shift-issue.patch probably fixes CVE-2026-10305. (Closes: #1139179) * New Fix-heap-buffer-overflow-from-short-truncation.patch. Checksums-Sha1: 21d55fad49ec844a2cb4226e45dc32b0150934fd 21024 librlottie-dev_0.1+dfsg-4+deb12u2_amd64.deb 4ba90f5ea68ebf5485704027febeed7e6ba62405 2558636 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u2_amd64.deb 846198ae986cbb1ec780f66d0e850d3bddb313fe 167132 librlottie0-1_0.1+dfsg-4+deb12u2_amd64.deb 120cd759287b756b03952d9d108a4e2cb7d07dc0 7583 rlottie_0.1+dfsg-4+deb12u2_amd64-buildd.buildinfo Checksums-Sha256: ecc6c47fbeab3f0ebdb959bf38d34a1396b81730f4a57eb6a40ad5f3420db59e 21024 librlottie-dev_0.1+dfsg-4+deb12u2_amd64.deb d7ccad7c961815967a2901113a850812815ddc4d54f17fa9fd1727f6f888dcdd 2558636 librlottie0-1-dbgsym_0.1+dfsg-4+deb12u2_amd64.deb d84ad3351becac6b287df3596669e1706dee6cbaeb200595de83ffe7963846cc 167132 librlottie0-1_0.1+dfsg-4+deb12u2_amd64.deb be751a09e8745ec52ade15675f42dc956f4c63a7826fd995349bffaa4657e746 7583 rlottie_0.1+dfsg-4+deb12u2_amd64-buildd.buildinfo Files: 4e8b311d7084e95f1573a79b4c6c5ff7 21024 libdevel optional librlottie-dev_0.1+dfsg-4+deb12u2_amd64.deb 1d8a9d4ad507bfdd63663eb2546a35aa 2558636 debug optional librlottie0-1-dbgsym_0.1+dfsg-4+deb12u2_amd64.deb 56c1d7c74193b7f8834d9100333e351d 167132 libs optional librlottie0-1_0.1+dfsg-4+deb12u2_amd64.deb ff6b71b37864589ad21da6dd281c8f44 7583 libs optional rlottie_0.1+dfsg-4+deb12u2_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7cQ9mRD4+dWjjrb6PkCWRKsh20cFAmpI5WQACgkQPkCWRKsh 20fMJxAAm9bOG86cAqzWz3ssTKP+Q80jyC9fuaT7lKnJnzEJGnT8kkBxLxCRv4q0 aVA6aesIfmGkDQ7bcnIryD9XbdlyFBWtyCl2/sr8oodsExrJgHEyLApNUe2RAwA0 BRFYuRwUmC7BYCLUFbEzBCMfUp5irI/rGDlABkKVDDWz/T5AkGh4Bck56DOZkxy6 9hSO7/RLsduMS8/euNN36XsBjoBeP2bjwAxvAq5kxsiQCmeVBFMPK43TU1KgAULi Tk/nzKWeB/eGiOGHwQ5YvRUyHHgvc7FVQKMrxryX2p5yutRQE+zpQxaojWzGMumd k+IoEWr3ZZYiYv37ERPWg024rM/E+FtJWIBylA49dcFoB49Hs/9Xe6dZMBh1TI2y uaAQZ22VFxEYhwiE032CWI8YxCLM7yKNpkI1qOr3EVcFvDTusIinMYeyqzsyx6sT QK+pkxcvZ8wfFlCOp/UBh3j2heZA/I8vZwVnuAEVjgT3NJfPprdCYoWZDZ0ymnXT NNXXLOeufnFEiS+1gjP5wQbuzZACxrNCcDGY54iGWdbu4ROA8spuIhW6Y8ZWzs1H L0US0rmE9/XzDu65eQXyoD/qhyItVHSqMqO6Zhy9s8RCYeaDUicRQQc3C75vpLB4 u7Fw9NCf5xCdZtyStNfv08KJ/CUwvXmf3SYawl8T6qLLX3ieChM= =Ch/O -----END PGP SIGNATURE-----