-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 03 Jul 2026 14:01:02 +0300 Source: rlottie Binary: librlottie-dev librlottie0-1 librlottie0-1-dbgsym Architecture: i386 Version: 0.1+dfsg-4.2+deb13u2 Distribution: trixie Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Nicholas Guriev Description: librlottie-dev - library for rendering vector based animations and art (developmen librlottie0-1 - library for rendering vector based animations and art Closes: 1138919 1138920 1139179 Changes: rlottie (0.1+dfsg-4.2+deb13u2) trixie; urgency=medium . * Fix off-by-one error in Fortify-FreeType-raster.patch. * Add Fixed-vpath-potential-issue.patch to fix CVE-2026-47319. (Closes: #1138919) * Add Limit-recursion-in-LOTLayerItem.patch to fix CVE-2026-47320. (Closes: #1138920) * New Fixed-signed-shift-issue.patch probably fixes CVE-2026-10305. (Closes: #1139179) * New Fix-heap-buffer-overflow-from-short-truncation.patch. Checksums-Sha1: 6ec604d4f0930b898643afd32b6b062adc3f2815 21184 librlottie-dev_0.1+dfsg-4.2+deb13u2_i386.deb 7856ec81ce98361d529e5fceeb332d75ee356747 1982144 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u2_i386.deb a624cd9be7cda7b757d88d69a7c627fc202a9f6a 122380 librlottie0-1_0.1+dfsg-4.2+deb13u2_i386.deb 8207e4cd562f3bc61ae3e4159f85e8e6fd99a04a 7386 rlottie_0.1+dfsg-4.2+deb13u2_i386-buildd.buildinfo Checksums-Sha256: 2fd87d8a9c306baf199d844d543be1f606b50c439b44f1a8e65e041b1dda870d 21184 librlottie-dev_0.1+dfsg-4.2+deb13u2_i386.deb d219a536603b0546e0049647c82550a9d56fa4529fed441277e06e28f7507ff6 1982144 librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u2_i386.deb 8981fb088468e6b035cf722ac2ad6c836dbc87977d7d047bfc5c2593ad005eaf 122380 librlottie0-1_0.1+dfsg-4.2+deb13u2_i386.deb 294836da9d07d78f0684d60f01a7dbb0b5f6d84513a0961922ae736339907694 7386 rlottie_0.1+dfsg-4.2+deb13u2_i386-buildd.buildinfo Files: be28c22dd3867522781db40bbd07e8e2 21184 libdevel optional librlottie-dev_0.1+dfsg-4.2+deb13u2_i386.deb 4067bb50759172dd30555d759b39a4c0 1982144 debug optional librlottie0-1-dbgsym_0.1+dfsg-4.2+deb13u2_i386.deb 52fd5d38f5dba1ce3bb905f7a9bbe629 122380 libs optional librlottie0-1_0.1+dfsg-4.2+deb13u2_i386.deb a0ba832b3ec53d2881122038437f4797 7386 libs optional rlottie_0.1+dfsg-4.2+deb13u2_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE+i/sCsF3puL4e7qIGNGWmfrqILEFAmpI3M4ACgkQGNGWmfrq ILG7ew/+J3wUIZhhOzizJ8r8n0YqX+y69h9kdHvr3xJnA3lDqUNPg5Ee22TbRLJ7 nDDgv0hCJFaOsMgpL2LSJdG7AMFHOw8GXfPiWiZGG+3vkxTTchFj7VtYkC1DS/Lr gNFVAGPCVp05QHIc+LxGeBnPyRcOvqVFO+avRJYs3NEDBtFiEhMtidsFSddx0E7j HYAChaAAh9/v5WQJfGLDjv9ttqiDxWIcyo7vePts1q6Y/fMX2K21tg+wEoK3hXRB Z2LwSMYgF53KwM9m8T2biYrH34JYofGuG7NfCHhNYx0dtiJUoEVIuPsNZCc6Ny4u vaEHWWARhCRi7qa6QdqCk9S/yX+YnMIomyN7jH1AG5GEhvGAQatXMmNmS6ltkbjO qr7MgRNzIyZF/XqUa6/YtTCqt4Z/n1EFG3Ay0wy9TVWA1FmdFl9xyXwZtcXwLydk vQ+nxFd//sRzAGrccAHp3awZFaXj2io71snu4p53qjDmG44WIH+cKe0SPQKiFXhF iXMCGsyGdTwNo0haXIdgrfIjxv5knrTqWrqxZQlRn3ZFgs9Y9NpLPgxMwApmjvUI udOdKRdzorYYGi/oCkEJ2vM75Yy8SBssZNxz4kW9p4xzK9uDOqKc9+m9BFREeEhi 3XSrEiFPB6bdONRGXgmXdwNYgnrQbcSKwet8gKEdGXqNya37/Is= =qpLT -----END PGP SIGNATURE-----