mspack-tools-debuginfo-0.6-lp152.6.3.1 4>$  ApaF/=„,)Y4-WOź,CÚ/#w؛LOI:8`3QVؐs" -hjDQws3:lb:ye}yb\ ^PP[5i61\g{£RSU[Kk}j,DK.d@dU[{hBf!os4*!vxlM|hKв^XR QRVhuhg\b4k~ҹ(<><쯧@ƽ_,ЁdC)VP߮܃RldrǕE3f9͹}YP+1yZГ4Y0,kt/k>:^}?SxزU0fy%k&JI? -5w n$h?^60_R[77^ RNOf/ |*aS\">p@`?P ' R'09 Rd  <   \tp(8 94 : K FPGdHIXY0\]D^R b&cdbegfjlluvw x\yz Lmspack-tools-debuginfo0.6lp152.6.3.1Debug information for package mspack-toolsThis package provides debug information for package mspack-tools. Debug information is useful when developing applications that use this package or when debugging this package.a=lamb10openSUSE Leap 15.2openSUSELGPL-2.1http://bugs.opensuse.orgDevelopment/Debughttp://www.cabextract.org.uk/libmspack/linuxx86_64J!LH!LGhQBp9AAAAAAAA큤a=a=a=a=a=a=a=a=a=a=a=a=a=a=aKristyna Streitova Marketa Calabkova Marketa Calabkova adam.majer@suse.dejengelh@inai.demardnh@gmx.demardnh@gmx.desbrabec@suse.czp.drouand@gmail.comsbrabec@suse.cz- There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (CVE-2018-14679, bsc#1103032) * libmspack-CVE-2018-14679.patch - Bad KWAJ file header extensions could cause a one or two byte overwrite (CVE-2018-14681, bsc#1103032). * libmspack-CVE-2018-14681.patch - There is an off-by-one error in the TOLOWER() macro for CHM decompression (CVE-2018-14682, bsc#1103032). * libmspack-CVE-2018-14682.patch- add libmspack-0.6alpha-CVE-2019-1010305.patch to fix a buffer overflow in chmd_read_headers(): a CHM file name beginning "::" but shorter than 33 bytes will lead to reading past the freshly-allocated name buffer - checks for specific control filenames didn't take length into account [bsc#1141680] [CVE-2019-1010305]- Enable build-time tests (bsc#1130489) * Added patch libmspack-failing-tests.patch- Added patches: * libmspack-resize-buffer.patch -- CAB block input buffer is one byte too small for maximal Quantum block. * libmspack-fix-bounds-checking.patch -- Fix off-by-one bounds check on CHM PMGI/PMGL chunk numbers and reject empty filenames. * libmspack-reject-blank-filenames.patch -- Avoid returning CHM file entries that are "blank" because they have embedded null bytes. * (the last two patches were modified by removing unneeded part in order to make them more independent) - Fixed bugs: * CVE-2018-18584 (bsc#1113038) * CVE-2018-18585 (bsc#1113039)- Correct mspack-tools group to Productivity/File utilities- Correct SRPM group.- Fix typo- Update to version 0.6 * read_spaninfo(): a CHM file can have no ResetTable and have a negative length in SpanInfo, which then feeds a negative output length to lzxd_init(), which then sets frame_size to a value of your choosing, the lower 32 bits of output length, larger than LZX_FRAME_SIZE. If the first LZX block is uncompressed, this writes data beyond the end of the window. This issue was raised by ClamAV as CVE-2017-6419. * lzxd_init(), lzxd_set_output_length(), mszipd_init(): due to the issue mentioned above, these functions now reject negative lengths * cabd_read_string(): add missing error check on result of read(). If an mspack_system implementation returns an error, it's interpreted as a huge positive integer, which leads to reading past the end of the stack-based buffer. This issue was raised by ClamAV as CVE-2017-11423 - Add subpackage for helper tools - Run spec-cleaner- Remove problematic libmspack-qtmd_decompress-loop.patch (bnc#912214#c10). Version 0.5 has a correct fix dated 2015-01-05.- Update to version 0.5 * Please read the changelog; too many things to list- Fix possible infinite loop caused DoS (bnc912214, CVE-2014-9556, libmspack-qtmd_decompress-loop.patch).lamb10 1629454397 007e8975c0bfc6a8d2d4f62e0406a00b294c542154c66e757a7d3d6df28519fde37c10c0b36f9e40642d3e8ccb18682de9b9a975c90123f9195efc11d393a2570076b1d3b3015d3ef8fa745bcdffe0e40.6-lp152.6.3.10.6-lp152.6.3.1debug.build-id007e8975c0bfc6a8d2d4f62e0406a00b294c54217e8975c0bfc6a8d2d4f62e0406a00b294c5421.debug54c66e757a7d3d6df28519fde37c10c0b36f9e40c66e757a7d3d6df28519fde37c10c0b36f9e40.debug642d3e8ccb18682de9b9a975c90123f9195efc112d3e8ccb18682de9b9a975c90123f9195efc11.debugd393a2570076b1d3b3015d3ef8fa745bcdffe0e493a2570076b1d3b3015d3ef8fa745bcdffe0e4.debugusrbincabrip-0.6-lp152.6.3.1.x86_64.debugchmextract-0.6-lp152.6.3.1.x86_64.debugmsexpand-0.6-lp152.6.3.1.x86_64.debugoabextract-0.6-lp152.6.3.1.x86_64.debug/usr/lib//usr/lib/debug//usr/lib/debug/.build-id//usr/lib/debug/.build-id/00//usr/lib/debug/.build-id/54//usr/lib/debug/.build-id/64//usr/lib/debug/.build-id/d3//usr/lib/debug/usr//usr/lib/debug/usr/bin/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:16844/openSUSE_Leap_15.2_Update/a484bd006f4ff339c7734d5e8d4b3c5a-libmspack.openSUSE_Leap_15.2_Updatecpioxz5x86_64-suse-linuxdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter *empty*, BuildID[sha1]=642d3e8ccb18682de9b9a975c90123f9195efc11, for GNU/Linux 3.2.0, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter *empty*, BuildID[sha1]=54c66e757a7d3d6df28519fde37c10c0b36f9e40, for GNU/Linux 3.2.0, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter *empty*, BuildID[sha1]=007e8975c0bfc6a8d2d4f62e0406a00b294c5421, for GNU/Linux 3.2.0, with debug_info, not strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter *empty*, BuildID[sha1]=d393a2570076b1d3b3015d3ef8fa745bcdffe0e4, for GNU/Linux 3.2.0, with debug_info, not strippedPPPP'P,B,xJlibmspack-debugsource(x86-64)0.6-lp152.6.3.1utf-8604ef7d55797d25f57a398e83dc670840690f08b75416296dc0e1eba27250791?7zXZ !t/"9{] crt:bLL PoWDo?z'g} n_@ -`qxC3A.( 7 {K-tt c=֞0e5"^E%]ާG=A!/rOGgWBILT ኻX\ĂH ) nzd#sPFBܶ׳2MYKF1. :'?90/T6aQ4\, 9fO#\+i4cj'o- K ^/Wձ$wNd~v*A)Tt~0XPqPADƇyρغߕ;6G{$YK( i! ,#'%[BLLFfD69qDZ*^J_X l&B)w2Rm0ݧ/I7Jl=t*{U9bӪ$4_%5 \T4i|e=~O#GޫB Ye'yXvwԝb("=?yd$() 1=N=泍UtnD&p> !MF[[![@E슢Iy&]I<Қi>\ )9 5*~wKm 3B~at(IPGi9^Ӈ۵ yzdyM-Q1_Y=uŪǴ CɎYjTo"&2Oϯ#|@dg%⾨Da퍞ïup /fzdK?9GQHo(Lf~p9Nh}Ӱ|AKA҅VzT zbsdn9fV0է (3=ٍSId>1lrE( QWc?񣱩a"..Ak%'zN T/T5кxg<7瞟<hE O޿-GȰ9{tQ=Jг1M0Swqbr O4IPr6pLq0rF;{]eYG9M_A0`&؁[Qk~UOցR(vvjFL>yqC*#MHa٣jFtKt_ϲɈlG[%,DBz+g C]wam!2|Si σp\,4ňja; u~fej2nX!PsAq U|kH/oO墢K$tG|}mg<2}g|F4Šp !PRKWFBL̑[Vhh ChYߖ'hCh/Rw؋?fxPiNqiZAwcoV2ҀRkƫfŤj]'x~NexBQ ܮGe."Ɩ#Z|rWfK\U<ǒ?~'36Oŧ1+]y^m_G}v C'b5W#"堓4^ߔj\B6!i76a ֏&,k%j?6"!xz"8<`ƕk[ԁfܺY uv_^j假 z=PIۄ-Q0Kι:ͪm-Vb԰r+ڒPpwKoYԇgC.}vdyhf}ZI7=X-CKlu's|K#Hüˏg~erNJgL.QaH5d$O+ iv@DM+.8*%ܒꑬTgSBhcA&GHJcl=O,G\#Z'ÙL4 1iR< 8WsL a }"%V's.?R1)|b"n! _Vqoq?sG)hu {͝4LJan-;1Oۭl 6gݬGgG ~=Ǻ=Sz-z*[3 ^r @"sˆUyjr7nGU:xL= ŋ馲ٸz"OM nk [^+͜TfIu"(\dEw[:sb74 ^ǂ0qi$DBB@LUq ڇ9(E Uc=ʊ8 D\[.~f9dcd7T1Ep&J5gн~zM"X敉T`d$Kb cPWߍO3PY~@Kr3Ⲡ<0T+3HvS 7Ψ9nBwɌ`Cz=V0uH+X(rM:XɴWd^Z%"׍Um&=˲jEn^_y H RXzG) ;XuR7R $iI$M.4Rc t%z6Ix0AھH]R5q%^f=eEV`\| .?f*שX{ |2FTzNv>5P[d[AHJoiCs:D -+70*Abn]/"|Z)E }Աk<}I.W*$uXB/(=N8~BZ_L:یJ %7N"ӜHl"58EG|<9ᡯIɝ-cJJ cɀzjuTgr[*9H0G4kQ$ԍyoS. 3)+5zeҤk>8dicWQDD8 L\iKs 7`=@.6 g yl& !apc)*:W߽`5Ȥ|bhGȔnD+fśRq]OGx<@$ lhpDp֊ ⤭&Ɲ5BCznZ9a1\0I ]X'Z9 abrG[;(gt)-O/ة ?V=0)>|m5zDRH6g0gCLw|.gpV6!mS~ֿL5waֻ%tC6B tC9%\X;T"|-SKu 2*N-Q#;Owɔřcc!Ynj«!7BsK0{J8_ؤ"NS2@|TYJ9|"2C_R.IΏV>ioVh4^әB\}}-`8tzA!:]7-R3ovyy9p8烺ȆMlxwOqݐЭk@V}W,w "B/7Өaaǧ7:5PKx^;-:VEo:1ϲ1Z<L#'.7p RcZ\IxϯݏQjb A6M#OGQh7]?d Չ&E4+V0Q{0861Z 0A<޽!dVr>F4 {Y lhxx@ 4Q7 vFKvH?G\ 9!f1ݣ&h0NQQkȥWl?M#rTp/G$@ hdq 1׋_cLB R>.$oM~/=.VU+}!(9ggM;6cdԉPbX[| =ε;CU">37|fǃ)VA}BT~35{5cnP aáB; Rz 똋7FwI"HD,sfkU`_,r{3Jz R#!3V>`!jm dT~b$ %D`aU =p@"ol Ɖ^5@ĕA2 ֮hϢ>Dg:.k(V+@?ʻ 1벋}۴o#,^l9*V(UhպXy\ewW.2z Vh0I_ϡ,5γɣdvgS`DgN[t$/(tt.MH±WOΏVgfJa(lc 3ial.w'X'ѵ,Si{C:~dabNx-4>.pߠ# .0LCf P^Ľ+4R $Y%վ>HĖס`继yd6מ,9ގ{{R%\C",8+Ysy|R5iVN-yY}?ʏ@,Mۼ Z_2vߵ&\*>MB91,ipKc.̫sL@m| Bn6/P)O m|(PgL̢)nHbgz, ÍdzBT*+JXKGU(yAP⽗lQW@͊)^YdC;_5D<) ׋mgF 2[޹ 7K›W͔UA/lICej1:~ƶ~x]:cE)#'m+Lhۄ~!3^Bby7)Z AK~v'bqN)M,Vhiby3drw9Rx>e;(t"톝fHRЈ|Ե^w Bx5s9A4ff{4Si 1Qa3~2/m~^CRNbun'xKQ1U[tSO<-%7/X+7Vqu1a|ٸ)s묲Î:Xڻo:j}?h8jO'`=W8{KQ1KeH2 7B9.Pg/C1!T)REXV5Ul֥xGU}E3Uap}."$7xvj;|V&4rA=XNY1 `pSYZZmI+QO)wcr[5- T1lN QK6%`ܵFd_pkg>U>׳=|fi^*C;`RBeQYWћnD݇uƍLķ~`o7~Kd1[ KDb{_$٩9dpvT\z`~*Kg-+LQZ}k`  )Y{)%f@uWC Q$Y-]Xoe$9SB";dwN \H=<¾|1n<>oOyx<G?t< ($uB;RrH&3 5+=hƇbd`sogE$slhA"[Zrtt2 _pؕ #X +Y>]w5 TR}v> yDH]lhC%Bwy&e ,i`A $d"o{4ZE&w¡}j䪭1Ӕ8vxUw|kiڮzƄP\[4M%S1Y֎7Z$I6i%oyt)HTi#n- wa h.)RTCDHR7WiB$dvE!kLBC&0v'Vg|ゼz#fA) - 3Y<8# ,(̦p(sWɊ-1M!ְL<\p7vn4J4ims1{U 5X4]Ȣ6 Tuut>n̲CqObcŵIB9X '*QQߴa4c#^y7f\jpbePo 0?$ffhh!ϕ[qEt: jg=k)S%[Q7&D"vbܯKV:DQ  BGd gXzrY$y yׄ[yTj_o[f5}uc^FHăw9kwTᰡu,AOeVw!GVE;18@M_ ۚ|6."f$}bpݞv,Ѯz|Bo47!1dm` |>>si&VõqD؈e򭷓a*,x$qfo:|~ũ/!Ytl;p1nD{LnY8+~(gePK8fkR޷1^*M{X'B⫊=6.{QZ(#ݕe?)I43NMcĂHhy" @@Er[\|Ax b-†[D%÷  oLZmq)P>n9BWDQ|TW͎gt&?د!6q+_=fePk:j[noiueQ&}%PLb܀t/`4w+{68̂%$ $-ʫIr-Ե۸9-#*RJKwIbyܤ SEfq4E*)婞6vSاBo2*]vqYG~O fr`q/ F^՟rZ >ݻN (}?S͠Ęj