-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 06 May 2024 21:28:59 +0100 Source: glib2.0 Binary: libglib2.0-0 libglib2.0-0-dbgsym libglib2.0-bin libglib2.0-bin-dbgsym libglib2.0-dev libglib2.0-dev-bin libglib2.0-dev-bin-dbgsym libglib2.0-tests libglib2.0-tests-dbgsym libglib2.0-udeb Architecture: i386 Version: 2.74.6-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Simon McVittie Description: libglib2.0-0 - GLib library of C routines libglib2.0-bin - Programs for the GLib library libglib2.0-dev - Development files for the GLib library libglib2.0-dev-bin - Development utilities for the GLib library libglib2.0-tests - GLib library of C routines - installed tests libglib2.0-udeb - GLib library of C routines - minimal runtime (udeb) Changes: glib2.0 (2.74.6-2+deb12u1) bookworm-security; urgency=high . * d/patches: Backport GDBus fixes from 2.80.1 - If local users send signals on the D-Bus system bus that spoof a trusted sender, do not deliver them to signal subscriptions for the trusted sender's well-known bus name (CVE-2024-34397) - Fix a use-after-free when subscribing to signals with an arg0 match rule, originally from 2.79.0 and necessary to make the test for CVE-2024-34397 pass reliably - Add a local backport of g_set_str(), required by the above - Add proposed fix for a race condition that can cause a unit test to regress after the above * d/gbp.conf, d/control.in: Use debian/bookworm branch for Debian 12 Checksums-Sha1: 76d079604ed200984aeb94becf1b9fcb29b582d8 11248 glib2.0_2.74.6-2+deb12u1_i386-buildd.buildinfo 8f3ab4663e9455c679a79d8707f9f021eb4fb1cf 3327856 libglib2.0-0-dbgsym_2.74.6-2+deb12u1_i386.deb a70aa02707a4b9fb0983d0e46da3a2bc6d018778 1469956 libglib2.0-0_2.74.6-2+deb12u1_i386.deb 5f8bace5aeccf35965e1970f957c8b5341cb62ab 131524 libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_i386.deb 24fcb328b738937b5e47aee7006bbada5c11290a 113528 libglib2.0-bin_2.74.6-2+deb12u1_i386.deb 8408b6084fa092cceda28a6753b2282607aee563 65680 libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_i386.deb f6bd6d3e1cb0bbeef4cc2a1801fb6010525bfde5 151332 libglib2.0-dev-bin_2.74.6-2+deb12u1_i386.deb 8e77b890e19ab0a4c22292703d593b0c65272593 1720588 libglib2.0-dev_2.74.6-2+deb12u1_i386.deb cb5ceb9b40bdc06bc8aa369827ce979aedd8f05e 3993840 libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_i386.deb a1a0af80dfab3b3f53b575e4a05b69f0c56bca54 1771212 libglib2.0-tests_2.74.6-2+deb12u1_i386.deb d01a7c4a7bbec701c47d4db4d477ac0778be18c9 2333136 libglib2.0-udeb_2.74.6-2+deb12u1_i386.udeb Checksums-Sha256: f73be2bcf2afa3e4c08eb521e4218e0578989b7b8afb19850ab6555cec807a6c 11248 glib2.0_2.74.6-2+deb12u1_i386-buildd.buildinfo b3a8ecc3dce01bd918404bcc8669413e1368a5e97fd770aa8dd31ce021c74864 3327856 libglib2.0-0-dbgsym_2.74.6-2+deb12u1_i386.deb ef4451fc7d08c41090a993e9ac35b433fdcfc1018abda95202ec8027057f868b 1469956 libglib2.0-0_2.74.6-2+deb12u1_i386.deb 116764d07e543cef7c924f6e8c4809ef4609d0225bc0b4bbcec81921326fe00d 131524 libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_i386.deb 4f8507a77d402b4673b69d0e98906fed0518ba5d389e3ec5872755fa9d358428 113528 libglib2.0-bin_2.74.6-2+deb12u1_i386.deb 3edd83ab07182438201b56bfa3086ab7bf0ac8851b5d864368a34154d96b9317 65680 libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_i386.deb d9faf025a9defb2caef345817c5e4e8033fe2a777e2c0a0373f13f0a6408d14e 151332 libglib2.0-dev-bin_2.74.6-2+deb12u1_i386.deb 9ec75f940cf01314d411ec80e3f5eeb5efc1604815bcabf02212ecc6825274be 1720588 libglib2.0-dev_2.74.6-2+deb12u1_i386.deb 161c3c4ba54b8b0c33769ce1c5561ac32c413d3c61c4fd8124b07bedb60472f0 3993840 libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_i386.deb 15c9087cc2762e543fa1f91b27f1135ab16ae178f337adc20c591e2b243e828c 1771212 libglib2.0-tests_2.74.6-2+deb12u1_i386.deb 1d30bdedd089f73b1f139fe92b03cde8e8c09079aca9499077cef386040cfe0e 2333136 libglib2.0-udeb_2.74.6-2+deb12u1_i386.udeb Files: e37bdce703a19ee3656abfeaa46a035a 11248 libs optional glib2.0_2.74.6-2+deb12u1_i386-buildd.buildinfo dfb9510c534b0691c2ae5da3eb9a4a9a 3327856 debug optional libglib2.0-0-dbgsym_2.74.6-2+deb12u1_i386.deb e207f3133d35a174f81710e9e6b4cb94 1469956 libs optional libglib2.0-0_2.74.6-2+deb12u1_i386.deb 045416ec8ebfdea1f355b8813a37e57d 131524 debug optional libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_i386.deb dfa00c9f4fa4a7effb28bd2df1c602af 113528 misc optional libglib2.0-bin_2.74.6-2+deb12u1_i386.deb a0776c52379ad34832b2182e3440e5ef 65680 debug optional libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_i386.deb 01157e247480aa4eebe265390e43f88a 151332 libdevel optional libglib2.0-dev-bin_2.74.6-2+deb12u1_i386.deb 371ff13f2cca7a717b46455eb532415a 1720588 libdevel optional libglib2.0-dev_2.74.6-2+deb12u1_i386.deb 0cb4184277ef0eb7eca75fa2997bad99 3993840 debug optional libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_i386.deb 432665c21086dce94ed07d923c6d8f24 1771212 libs optional libglib2.0-tests_2.74.6-2+deb12u1_i386.deb 885e5153306e8f996298ceee3becb0e2 2333136 debian-installer optional libglib2.0-udeb_2.74.6-2+deb12u1_i386.udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErEDrIdpJkzFMm6K+PyQET5WCY90FAmY6OwgACgkQPyQET5WC Y92bKQ/9Eu8U9vSKMBG8pc5H8OT2xGfnJX3Cm47vtZ4bZdqsl3FsoW7Xihcu/nAJ qfb4/boGGUi0D6Qk6L8myUteCTiJ+dbus7F19n/OJBikDPNFnej+yIvP75d2Rz0+ v0IDCJlcTdYk1sem6Roq2UqG78+D2Wfqe7mGP1LZd+H7K4z141Ht6617NgMFHNQv sCPJTkr6Z+65q6UFbUct5AJIbhHz67yioBfi/18TKUU+siPDnbOz2DQkn1Tr/quY yVuebBv1qAng/o7x7MTPl0FhQJuY+GLRL1g9Jkcsz9Kf2Obibe0UsqsM2Do5dgDX X33sK3xzbiK51wICHVyh3ul3rZCzA+lpvHISDD2clHnteN4QJ5g6O8xa1ORR8a5l yfIVe67BJXNnNUYwkvz2z0hd8Ot4vUN257R/2RQ2s6ebcm98rNAH8RpZboasp93c IKbU4pfQXCOw0S4PFvZ2UubMERHYBh4gGqR45R07FVOLH0+B7BNdTbWXjsDueFGI Q7EqSiiUAw+BJwrD0H/NvbKZfQnKji13M2wWbNV4iFGD3eyUmRRaryTc3Xx6aGvn Qd4dewt5vydOpqcEcYXKfc+pKxYJgZ7sL/dSpXzBpQKQj4nYWEWyd5iyDT4wRzzJ wwWXKFDr9QFr1X3M1p2azNSMKfssaoV9FnECYXgLdGxNyFPyQEU= =UY/4 -----END PGP SIGNATURE-----