-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 06 May 2024 21:28:59 +0100 Source: glib2.0 Binary: libglib2.0-0 libglib2.0-0-dbgsym libglib2.0-bin libglib2.0-bin-dbgsym libglib2.0-dev libglib2.0-dev-bin libglib2.0-dev-bin-dbgsym libglib2.0-tests libglib2.0-tests-dbgsym libglib2.0-udeb Architecture: armhf Version: 2.74.6-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Simon McVittie Description: libglib2.0-0 - GLib library of C routines libglib2.0-bin - Programs for the GLib library libglib2.0-dev - Development files for the GLib library libglib2.0-dev-bin - Development utilities for the GLib library libglib2.0-tests - GLib library of C routines - installed tests libglib2.0-udeb - GLib library of C routines - minimal runtime (udeb) Changes: glib2.0 (2.74.6-2+deb12u1) bookworm-security; urgency=high . * d/patches: Backport GDBus fixes from 2.80.1 - If local users send signals on the D-Bus system bus that spoof a trusted sender, do not deliver them to signal subscriptions for the trusted sender's well-known bus name (CVE-2024-34397) - Fix a use-after-free when subscribing to signals with an arg0 match rule, originally from 2.79.0 and necessary to make the test for CVE-2024-34397 pass reliably - Add a local backport of g_set_str(), required by the above - Add proposed fix for a race condition that can cause a unit test to regress after the above * d/gbp.conf, d/control.in: Use debian/bookworm branch for Debian 12 Checksums-Sha1: ff8498fa97b6276afaf1d576738bac4023a660eb 11207 glib2.0_2.74.6-2+deb12u1_armhf-buildd.buildinfo e9d452b4ccdd40f382db59e53fac590e556df8e6 3909736 libglib2.0-0-dbgsym_2.74.6-2+deb12u1_armhf.deb 362d94dc5142bc45e6a32f3d07a702c929400978 1228980 libglib2.0-0_2.74.6-2+deb12u1_armhf.deb 05bfd9d51f3b0d396e4c5e1ff4ec5282df5067bc 144208 libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_armhf.deb b43e83b67008ddf5c5a0c175c3ac4a02997d5c4e 103288 libglib2.0-bin_2.74.6-2+deb12u1_armhf.deb a760e9c5e6f0c1b0f8cbccf87d670ea60c424d81 70720 libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_armhf.deb 85ee9d09548c1f0d8bb872d12b47c26aa8cd6043 147676 libglib2.0-dev-bin_2.74.6-2+deb12u1_armhf.deb a7c9551ad1cb3cd27e2afb52169b1b288beda511 1482316 libglib2.0-dev_2.74.6-2+deb12u1_armhf.deb 5e19961e46af0b621b7f6a756298e277a6c62bf5 4302892 libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_armhf.deb 3d4f72e30d59c490428ad21b955ff7c0f7e391c6 1755168 libglib2.0-tests_2.74.6-2+deb12u1_armhf.deb 6c9ff85ee705c668bb84943200ceb4eb0f1885a9 2097480 libglib2.0-udeb_2.74.6-2+deb12u1_armhf.udeb Checksums-Sha256: 8688d7f95f143b52a39bf6e6dbc045449bce9c7cd5548ae66499634d438b8845 11207 glib2.0_2.74.6-2+deb12u1_armhf-buildd.buildinfo 81fd3651615952f165647da3b4bb4455c943ee5b7d2b018523d7c24a9fad0dab 3909736 libglib2.0-0-dbgsym_2.74.6-2+deb12u1_armhf.deb 8eeddfc8d08cb60e66c5d9b7864a71904bf4cd80d03176a7a015ff7ca22c1404 1228980 libglib2.0-0_2.74.6-2+deb12u1_armhf.deb 4d25867d6a28d87c81f45b7cac466ef820cc7409f5ef2ee46d6a05189a7823f4 144208 libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_armhf.deb 126027b10f9009aaa50d61ae1cdf7bda751cdec76350510a0e87a6d4199bbf60 103288 libglib2.0-bin_2.74.6-2+deb12u1_armhf.deb 4e4879839d4974d458231ccf34f1c1bd8491edeb4af774293734f162cc5fb041 70720 libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_armhf.deb 5f5340e59616ab9acdfa6895d4bdfa9383ec991688f10a31ef9d089ae84c4714 147676 libglib2.0-dev-bin_2.74.6-2+deb12u1_armhf.deb f68e4ed891ee172ffb3836055fcb5774df93b4b5ba6b7134b1ca90ee8ca0d482 1482316 libglib2.0-dev_2.74.6-2+deb12u1_armhf.deb f1f1dd7593c8a916d9bcc8cb492a7867894f5acf7e241ef6e9c54aff8c2d049c 4302892 libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_armhf.deb 61c853e2cd70125274d8ca5d7e885324afe927171120cee912d1b40e2d654747 1755168 libglib2.0-tests_2.74.6-2+deb12u1_armhf.deb 642090a07b840c902bd51f1793c23e22fea37db494acea8899556287843b2085 2097480 libglib2.0-udeb_2.74.6-2+deb12u1_armhf.udeb Files: d22568f6b1eea48f0b8da840b779da40 11207 libs optional glib2.0_2.74.6-2+deb12u1_armhf-buildd.buildinfo ac701d96d6fdd5cb8bfe36260b1318b3 3909736 debug optional libglib2.0-0-dbgsym_2.74.6-2+deb12u1_armhf.deb 2f28e8eb42caab60167d33b30b55b2ad 1228980 libs optional libglib2.0-0_2.74.6-2+deb12u1_armhf.deb 1770de358ebeb9ce89fa90b4da75deed 144208 debug optional libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_armhf.deb d54b4952ae7aea8b7e5c5f7ebc8bab29 103288 misc optional libglib2.0-bin_2.74.6-2+deb12u1_armhf.deb ff77807c0bdd3dc5f9a1f23c07666e28 70720 debug optional libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_armhf.deb 782120bebf614ffb73584aa4a32a3e4d 147676 libdevel optional libglib2.0-dev-bin_2.74.6-2+deb12u1_armhf.deb 0ce81338090230698375d73ce16efc43 1482316 libdevel optional libglib2.0-dev_2.74.6-2+deb12u1_armhf.deb 3ec75e46b92bdfc50a164b9921e257f1 4302892 debug optional libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_armhf.deb fcd0e17e9228ec797436fe99669a0516 1755168 libs optional libglib2.0-tests_2.74.6-2+deb12u1_armhf.deb f27243dfe63853636a7f71d63988d20f 2097480 debian-installer optional libglib2.0-udeb_2.74.6-2+deb12u1_armhf.udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEElif5H+pIB11ZS5Aay8vyjiVDuNYFAmY6OvUACgkQy8vyjiVD uNYdPQ//VhrMz5k0nY1f/8eEnuEOIHFOGGur0hPrJ+Pp4MEsqLqfyqGknUCLIqM+ NBPVd8H54sjud6wFMkuxBVxaOE6amTt64VTO3Vhvew5BiW7B/8B4NUhJP+PVo++a nJh0jaX2ZnWysikVNCndjNf+TqNL7sfpXDCUMv7O+xWc6tG7Xbve3TJBvsC1rcCa eL3Nu4pkYozNCKZdNH8rcWVFRJD7Y7ymWxHJqsOMp+tfuWpVZMdgUCDVa8FY0SEL 31qQTcmhAiUXGZp3wYvK/dX1noBkGN80L34clblsDmTU3576QxWF/uZ7Qp86iUmj ++JT98OSc7IgRUwi/jH0Iq+i+bsc7BfGdrhSh/w4VveuxiTW24B+or42X0s/6gMT KRffgUe98QljGqkvrZH3K9xphY3yWv4yCGnOwUwf17ItQXOvlU0wr0U7yhwTEz1c U9wNLmRdshZ3TR7tiKIED2q3vvMh+aVafGxfPS4L55L53N7GKgP1xBeTidDTjd/O 6z5suzjcTMno2AZ1qKlTjlGOns0oL9ie+M4IyJAzrnYonF7mzKlAcXYzqMht8uZv W8Fk5WmQsz9BAByiPIQCngUgwBXJZ+3ZLtewUbRVwmaTPLN5dZWPh08LfADRd4h9 YnC4Hn6AE2r3puc8VejLIenHsgIyO3gy1oji11IoIkTBrYPzX68= =vxN2 -----END PGP SIGNATURE-----