-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 06 May 2024 21:28:59 +0100 Source: glib2.0 Binary: libglib2.0-0 libglib2.0-0-dbgsym libglib2.0-bin libglib2.0-bin-dbgsym libglib2.0-dev libglib2.0-dev-bin libglib2.0-dev-bin-dbgsym libglib2.0-tests libglib2.0-tests-dbgsym libglib2.0-udeb Architecture: arm64 Version: 2.74.6-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: Simon McVittie Description: libglib2.0-0 - GLib library of C routines libglib2.0-bin - Programs for the GLib library libglib2.0-dev - Development files for the GLib library libglib2.0-dev-bin - Development utilities for the GLib library libglib2.0-tests - GLib library of C routines - installed tests libglib2.0-udeb - GLib library of C routines - minimal runtime (udeb) Changes: glib2.0 (2.74.6-2+deb12u1) bookworm-security; urgency=high . * d/patches: Backport GDBus fixes from 2.80.1 - If local users send signals on the D-Bus system bus that spoof a trusted sender, do not deliver them to signal subscriptions for the trusted sender's well-known bus name (CVE-2024-34397) - Fix a use-after-free when subscribing to signals with an arg0 match rule, originally from 2.79.0 and necessary to make the test for CVE-2024-34397 pass reliably - Add a local backport of g_set_str(), required by the above - Add proposed fix for a race condition that can cause a unit test to regress after the above * d/gbp.conf, d/control.in: Use debian/bookworm branch for Debian 12 Checksums-Sha1: 383320f385dbd4c193c6ab4ab886596f43c15452 11331 glib2.0_2.74.6-2+deb12u1_arm64-buildd.buildinfo 479704c49943c6f373c639bef611e246291b18ad 4049084 libglib2.0-0-dbgsym_2.74.6-2+deb12u1_arm64.deb 86b3251bd8165db03c8f52e0bda643da5ebcd665 1311844 libglib2.0-0_2.74.6-2+deb12u1_arm64.deb 38764cf1ff9195e90211a140b259e600f8081215 151292 libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_arm64.deb 56291f535d41ebfe428d9b88a5c4af08b26ce178 105848 libglib2.0-bin_2.74.6-2+deb12u1_arm64.deb faf04a8d4ad77ed6eacb7fd356bca7946a3a4bfd 72928 libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_arm64.deb c40082f6da1375f2e98cbd1744ee6972285cf2df 149788 libglib2.0-dev-bin_2.74.6-2+deb12u1_arm64.deb 605af04e8beab24c08e4d549cf3d85707b3daee4 1617220 libglib2.0-dev_2.74.6-2+deb12u1_arm64.deb bfe97e75b4b501d4d1cde161c0d4000cb407bd03 4827992 libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_arm64.deb 5b6eed8773b6079b59b098c4990e32953bb499bf 1684132 libglib2.0-tests_2.74.6-2+deb12u1_arm64.deb 4b2e74aedc41233c138a3e6558d944fc3bd6ed23 2180056 libglib2.0-udeb_2.74.6-2+deb12u1_arm64.udeb Checksums-Sha256: ad81bccb64356b787f9df51512dfa84ebd1b8da1e97761be9c80a8a75953aaf9 11331 glib2.0_2.74.6-2+deb12u1_arm64-buildd.buildinfo 0360250070ba0d5ace96aa9f74f992e5cd8e84091a398d21f07478ca072cdd19 4049084 libglib2.0-0-dbgsym_2.74.6-2+deb12u1_arm64.deb 3f59bcf321bc41aee1498329171976f6d47bc2b8827de8ceed673e53c7ee2c16 1311844 libglib2.0-0_2.74.6-2+deb12u1_arm64.deb 3d8e7ce27a9726accc3318a95497b6909cab0234103f4c3d5973c6e1a0ffcc59 151292 libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_arm64.deb 41a8af51f06666fa5cc86c65db739b38442e213027133ce97b40a7fc765754f8 105848 libglib2.0-bin_2.74.6-2+deb12u1_arm64.deb 944b5a8d78a77ca8a4602a6f07c9f338a457e525092880be0bcb570aad0257a3 72928 libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_arm64.deb 060db6260714f8de841c51f7983f46d2265205104c0e9712b15a9d3f2dd85b50 149788 libglib2.0-dev-bin_2.74.6-2+deb12u1_arm64.deb 81308baa8384c50aebe976102e14f8ca561886599ab1e2cc2479b0c5efcc0f86 1617220 libglib2.0-dev_2.74.6-2+deb12u1_arm64.deb b299ca272cfff4ea6119677a5f8e987174935ded3fea8c4172f933cb99a21969 4827992 libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_arm64.deb bbdea705826b60dcd4afc8716eaeadbeaa1a2ee1c97321e212dacf12972cd8dc 1684132 libglib2.0-tests_2.74.6-2+deb12u1_arm64.deb bcc585c331686de9a1f55881787a9ca3092fc93910831dc90fc3f0c0397af296 2180056 libglib2.0-udeb_2.74.6-2+deb12u1_arm64.udeb Files: 19f36aff366e3d1ffb2abf2f22548428 11331 libs optional glib2.0_2.74.6-2+deb12u1_arm64-buildd.buildinfo e3527e05c0778459e776b5ba946e56aa 4049084 debug optional libglib2.0-0-dbgsym_2.74.6-2+deb12u1_arm64.deb 6d0e4bcd0297583ae00dd58740e9570c 1311844 libs optional libglib2.0-0_2.74.6-2+deb12u1_arm64.deb 259adc092bc01aa9f4f821343b9b7f48 151292 debug optional libglib2.0-bin-dbgsym_2.74.6-2+deb12u1_arm64.deb e558dd713232d556c803d6ddda7f5ca8 105848 misc optional libglib2.0-bin_2.74.6-2+deb12u1_arm64.deb 57f09966c702e89580488c2ab27896ea 72928 debug optional libglib2.0-dev-bin-dbgsym_2.74.6-2+deb12u1_arm64.deb bd9f5b180aecc669bbd2298225a231f8 149788 libdevel optional libglib2.0-dev-bin_2.74.6-2+deb12u1_arm64.deb 0e48045729459a9120de2efd562dd91e 1617220 libdevel optional libglib2.0-dev_2.74.6-2+deb12u1_arm64.deb 6c399b60e035cbbbb6acfec1825952db 4827992 debug optional libglib2.0-tests-dbgsym_2.74.6-2+deb12u1_arm64.deb a3533c54255f790ed22a597c68251554 1684132 libs optional libglib2.0-tests_2.74.6-2+deb12u1_arm64.deb a965284e1043801a30425dada997f34c 2180056 debian-installer optional libglib2.0-udeb_2.74.6-2+deb12u1_arm64.udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE9C4sZYDxwNo9XoUDaRWK3AIe28EFAmY6PosACgkQaRWK3AIe 28E8Mg/+MiyMIDx9a93alLrAytC5XwYgXOEhI14SlXOTe7d4ZxA+6KO4RZlrLMEa NhR0+GuU14ERNSUon73sYKnaixiNLtF2r5gJ4qb8FmFB7qqnSwwjJWJbfF9dkp8g C/VtwTLQ2epuXuH4t32n1/mW/bJFOmUpw6fDt9x0kFTLZ0AdzMZW/ivxa60hbARv cPoDZnfPXmGNEeR8vFU5HdlNotOcNgp94p4ZEfDuPJsYFle0CXWslw2ZGRbI3gQ8 n2WdA6i4vES5NZ3cYz4/CBa+JEkQCXGbqCzs7+fyh0l+DaYucZA0DNeYl/nEIbKX aVIi3KOGVx2SqlYuE9tWAP1bo8LBe+uOPXtfRQF+yX4nSfXpfNEK2htFlP5oNC0g AQdir748C4CCMy4zPo3O+eTNDployLu6TwsC9sGEqsXjrdEg9pjFvAEV4nzu0pXH KzMiBJa4UoJYh6/SjTM4hkG7dZOYayZ1W4sRb11Ctciu2YX80UapqT2LOpa9S73B AEgNGufeojq9xEGGtNRu8ZBv+g1mx5UqXLUbMAOf4CHNj0zsRIrmVRQJi5TTiHpV Cz2ge5Atycq7hO6lUl4o3vTYSJp0Q9WRVVe9wrI8sFhnJbpFvSeYINb1TtuCh4Zm nIzeGZ1zOPxX8KiKxjtRWpcaB3+q7wF/MeRLl9oTTGVxnL0YBYg= =VWJg -----END PGP SIGNATURE-----