-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 06 May 2024 21:28:59 +0100 Source: glib2.0 Binary: libglib2.0-0 libglib2.0-0-dbgsym libglib2.0-bin libglib2.0-bin-dbgsym libglib2.0-dev libglib2.0-dev-bin libglib2.0-dev-bin-dbgsym libglib2.0-tests libglib2.0-tests-dbgsym libglib2.0-udeb Architecture: amd64 Version: 2.74.6-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Simon McVittie Description: libglib2.0-0 - GLib library of C routines libglib2.0-bin - Programs for the GLib library libglib2.0-dev - Development files for the GLib library libglib2.0-dev-bin - Development utilities for the GLib library libglib2.0-tests - GLib library of C routines - installed tests libglib2.0-udeb - GLib library of C routines - minimal runtime (udeb) Changes: glib2.0 (2.74.6-2+deb12u1) bookworm-security; urgency=high . * d/patches: Backport GDBus fixes from 2.80.1 - If local users send signals on the D-Bus system bus that spoof a trusted sender, do not deliver them to signal subscriptions for the trusted sender's well-known bus name (CVE-2024-34397) - Fix a use-after-free when subscribing to signals with an arg0 match rule, originally from 2.79.0 and necessary to make the test for CVE-2024-34397 pass reliably - Add a local backport of g_set_str(), required by the above - Add proposed fix for a race condition that can cause a unit test to regress after the above * d/gbp.conf, d/control.in: Use debian/bookworm branch for Debian 12 Checksums-Sha1: 0aec5b08dc3c5277d47ba4ba5b9b5da31e6250d5 11332 glib2.0_2.74.6-2+deb12u1_amd64-buildd.buildinfo 8006de72ea044810be29901a9312da70eeccabf5 4040284 libglib2.0-0-dbgsym_2.74.6-2+deb12u1_amd64.deb a032d148bc92a723d42be98520b7f8a452237a9c 1400872 libglib2.0-0_2.74.6-2+deb12u1_amd64.deb 6e07f156049f08148781fb6c89e886892193074b 152872 libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_amd64.deb c07d58a860841693b361a4939ecfe92c7d20ff3c 110156 libglib2.0-bin_2.74.6-2+deb12u1_amd64.deb e869124492629d3e1a68e6c6ac69b1510302f429 73476 libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_amd64.deb e10a7e3e0cd180a4431585707e3e0c167ed0f143 150892 libglib2.0-dev-bin_2.74.6-2+deb12u1_amd64.deb 116f0a80beaa7ca72c74501312708cb575194d81 1602920 libglib2.0-dev_2.74.6-2+deb12u1_amd64.deb bc9708ca930bcbfdc015263b48a9bf65a1aa85f8 4794856 libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_amd64.deb 1ddb26d05db5f01fc4f6dd8235db5b4b39425c5e 1862872 libglib2.0-tests_2.74.6-2+deb12u1_amd64.deb ecc6b18b1f5d4e431cdddecc154cabae517cd408 2269504 libglib2.0-udeb_2.74.6-2+deb12u1_amd64.udeb Checksums-Sha256: b793b415f09b5b315fffff9deead6d6ee5919bc7ec89521a3bc11fef4158acc9 11332 glib2.0_2.74.6-2+deb12u1_amd64-buildd.buildinfo 75ef7964717c13dd8bf6ba68307a443c128c89da109fa104ac53ecef632e2318 4040284 libglib2.0-0-dbgsym_2.74.6-2+deb12u1_amd64.deb eeb2666e53cf882974f61b6afd8331091fd0d5e9f53576fe14723e5de42675d1 1400872 libglib2.0-0_2.74.6-2+deb12u1_amd64.deb 22a4187eb62cdb6df3bf188747e2824cae12065a9871f248b936aab95c97e95f 152872 libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_amd64.deb 518c671d69ab92b93da5d9d46473dc342d68f0ebd334cf8f323fa53702a99da6 110156 libglib2.0-bin_2.74.6-2+deb12u1_amd64.deb 9089ca3f510ab8858bc5d2c163de23a2f4d8f65210cd1e7b857ef8ef9c9927d3 73476 libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_amd64.deb 8964f2861cde4fa1c0cacb6a9e2177d9c48e16b3240b43df3ccfbd17d1faf6ba 150892 libglib2.0-dev-bin_2.74.6-2+deb12u1_amd64.deb c787180d1f3c6e6ecc727be64944bf181ac20645feaca51d885f7d53964c3308 1602920 libglib2.0-dev_2.74.6-2+deb12u1_amd64.deb 2abf891b8193979664ef2f2dd7983b4ecc7f21e7d3d0f9232a9a10f7e023e6d2 4794856 libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_amd64.deb 428029d069ae6b5b3aa5832fc62f642d1339d0d2cdb2bdf903f26d6a21ea83e8 1862872 libglib2.0-tests_2.74.6-2+deb12u1_amd64.deb 01140dfde195d847a7dbd6b7a1556cc2e674e6e5f136f8b02218d72d848fbe11 2269504 libglib2.0-udeb_2.74.6-2+deb12u1_amd64.udeb Files: b036e76499d10e1d91dde20346bf534a 11332 libs optional glib2.0_2.74.6-2+deb12u1_amd64-buildd.buildinfo f1c6eabf81450815c77ec133242c83f1 4040284 debug optional libglib2.0-0-dbgsym_2.74.6-2+deb12u1_amd64.deb b3eee2ee9f52047bb4dcf2fdcb6c8033 1400872 libs optional libglib2.0-0_2.74.6-2+deb12u1_amd64.deb 83fc1982844ef55d1ac3be351f33d306 152872 debug optional libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_amd64.deb 81b0bc17c9a5eccf8af54823b7df5a66 110156 misc optional libglib2.0-bin_2.74.6-2+deb12u1_amd64.deb 72e13c047a30f33e5bcbed4eef1ecf69 73476 debug optional libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_amd64.deb bae7f31b7e07d08fe2c57695aa2607d4 150892 libdevel optional libglib2.0-dev-bin_2.74.6-2+deb12u1_amd64.deb 4e2ce2f068737fb87a590db6b02c9448 1602920 libdevel optional libglib2.0-dev_2.74.6-2+deb12u1_amd64.deb f2bf92d567b2ad1f522f53b6662bb762 4794856 debug optional libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_amd64.deb cdeb27d4a7a0a215f882f95d2d1ff63c 1862872 libs optional libglib2.0-tests_2.74.6-2+deb12u1_amd64.deb 1687816fa8024753c92407b2cc1387c4 2269504 debian-installer optional libglib2.0-udeb_2.74.6-2+deb12u1_amd64.udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Unr4QHS5Yi4rr9Q3KGKEAtjIVgFAmY6O0YACgkQ3KGKEAtj IViASg//YorMVG1HXduKnF3m1HASwbex6kI22ZWOvfih6MYmPoGQWr/iNgELGGOb +S3tWNkwCtii33g8K9FxuKzslpKPznulxuyQtFJsuOyo8wkV2HDGpqSml1SjAagv gVA2+KjjQ5k6i4+mEsUNwXdCqW31J8lzsaT8IOwxg8/B+y3+ieHpfjvOuLm7VIu1 3MhMr831qwWtH4LnUA9DBa03d4v9bjBfcq/llMpYHWqDdIBaqJR6MOLgOTOWXYLF 0nt9jHSg4ameFBJsw8ZNN/ttEUOX6JJXUXCYxfCLLAqTkhI3pYPNSXhO4YQdjGk0 CoeWxRuonhli6RSSBxatyIJAD9HmDYH7QXnJ/4Qan90syTb1qcw38jT7mRFJa7eG yGR+M+PR/acou+yrlWwktdxuIkKxSxXo5S2jKiLGUcyY3CqG/Oi/JyqX/jMTH6IY x3dzJXg9J8rJZ9h9DSq8+IydFxzM7LhbRjo+3QTroVnciNFszAjKCLZBX4AKzt0A qj74pPMwg6Y847ChGKxzaaXa9VGfql81wdnX2rRoQwVAEyCgzbGtYETg4uKTKGHV dJ+ntznDa6QEIFEg9GuLiikmK/klKjSWxm9fsuB+zHNF+cNmP9PcQwg3JUfXxeXi eNreCDvFj4FhXkwnHR6mh4kWWJI0A29TftV6+ZQu7EXyx0SnR48= =dK2o -----END PGP SIGNATURE-----