-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Jun 2026 12:21:21 +0200 Source: libvncserver Binary: libvncclient1 libvncclient1-dbgsym libvncserver-dev libvncserver1 libvncserver1-dbgsym Architecture: i386 Version: 0.9.15+dfsg-1+deb13u2 Distribution: trixie Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Sven Geuer Description: libvncclient1 - API to write one's own VNC server - client library libvncserver-dev - API to write one's own VNC server - development files libvncserver1 - API to write one's own VNC server Closes: 1138174 1138253 Changes: libvncserver (0.9.15+dfsg-1+deb13u2) trixie; urgency=medium . * Team upload. * debian/patches: + CVE-2026-44988: Add 0003_CVE-2026-44988.patch fixing Tight gradient decoding overflow (Closes: #1138174). + CVE-2026-50538: Add 0004_CVE-2026-50538.patch fixing attacker-controlled heap out-of-bounds write (Closes: #1138253). Checksums-Sha1: 3a246cb446a574ee4b94d408c4b5c54307547444 160960 libvncclient1-dbgsym_0.9.15+dfsg-1+deb13u2_i386.deb b1240b5678e32b411d07a432034dd477785dee74 200484 libvncclient1_0.9.15+dfsg-1+deb13u2_i386.deb 7eafbc5ee560e8c1b1d4f438bd0ddbaa2a7c0b97 216116 libvncserver-dev_0.9.15+dfsg-1+deb13u2_i386.deb fb5b3eb7ee5af1e3d8d2b2c1286acebbda53006c 309188 libvncserver1-dbgsym_0.9.15+dfsg-1+deb13u2_i386.deb 2ad3e26101c9fe9505fe622f54942a6e15ae7726 257888 libvncserver1_0.9.15+dfsg-1+deb13u2_i386.deb 5ade833c2acc838ccf22f3057863680fdf70beab 8736 libvncserver_0.9.15+dfsg-1+deb13u2_i386-buildd.buildinfo Checksums-Sha256: 682466394bd7bb457d3ed6c19a3f5e952fbf136fc406aae5c1206c3e953badc3 160960 libvncclient1-dbgsym_0.9.15+dfsg-1+deb13u2_i386.deb 5d865342919d24488c08f1ad62da1c49a20069275f964562b5445dace8df8777 200484 libvncclient1_0.9.15+dfsg-1+deb13u2_i386.deb 8eed145027d20585fa8fffeb2f949ea118a4f082a96c6f5fce07be600399f9dc 216116 libvncserver-dev_0.9.15+dfsg-1+deb13u2_i386.deb 59274c013d1acd6d945cb9df92174a157dfc6f519c2f3922da5484a431bab700 309188 libvncserver1-dbgsym_0.9.15+dfsg-1+deb13u2_i386.deb bdec335c8f27e76a3dfe400beebd01723655659fc14895dba35e07e9848b5db7 257888 libvncserver1_0.9.15+dfsg-1+deb13u2_i386.deb 3de3ad29a3bc47d5766f0b1539cfbd49a2eecb7ab56344abb71c14e7d70a7234 8736 libvncserver_0.9.15+dfsg-1+deb13u2_i386-buildd.buildinfo Files: e96f8d1b94e7fca384ce457d735af250 160960 debug optional libvncclient1-dbgsym_0.9.15+dfsg-1+deb13u2_i386.deb eb9e15153ee34a0f67ce68ad2a85f7e5 200484 libs optional libvncclient1_0.9.15+dfsg-1+deb13u2_i386.deb eb162755d59fee9720e0c01cd66f73ef 216116 libdevel optional libvncserver-dev_0.9.15+dfsg-1+deb13u2_i386.deb 3d05ed1bf440e06c1ebb5557ec6b10dd 309188 debug optional libvncserver1-dbgsym_0.9.15+dfsg-1+deb13u2_i386.deb 73f345986aac8bb51baba99e706dc57a 257888 libs optional libvncserver1_0.9.15+dfsg-1+deb13u2_i386.deb 4b4a90b7c9a8b8610ed7a67eea216420 8736 libs optional libvncserver_0.9.15+dfsg-1+deb13u2_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEPAUaMA0H0rOy6qBWf2INRiCdaWIFAmpGz+IACgkQf2INRiCd aWKaSg/9HaSVroXyFd3hALSBrT3aa9k6TwLn+7+HW/adhIdqVyh9GpXXzFyfqwvp iOd/V1GOBhSy/jR3HIjXmzCgvxBJEGPWXnXy4cgNhH/pdWCW/5/I3NPk/JF64i9n S0cLULNXybcwLOesXq014xhtbX/jQs8xqk8Ny4bWcnJKXp3jLGsOkCG4MxhaKURM Qk/GR6rOXIY/JoTXUBbOFTs9NadJC5/SY2Jg4imFbUpxFzTzkUjI6eqzGFddiB2m 9MP6HvGYg5XCd1NNGn35nSl672ofeKQ+FpnTpLySDYpTvtsKly7wfQ9xVHdrfURQ jcthQeyr7INs+EcqyUaUDD7VNCvk2KNCm9nI3lugw7RCeVOO0lAlK9SD2roAswmb fEtvHFmqmCNrZZR6TMIaMiTOjumrihXm8yU2a+/Q2kGjIpPSgDi++aV5IooXkmW4 zrOntkYVBljQt2eYXYNb3xBX6XYuHbzq9XY2z8fQcuO1iuFXukQCs0mWdY9v7ZS6 0VtEIUoAU41MTL5NPdA0VndMCIi/akRklyfPbCzANVisHrLZbDA6DyElQpxBpvMD 6F0BDCAy1eUlWVzq45Fi+XOZwukjmd/Zly3bKkrrjLwZHfia7dh+TgNbzGkwQh7j QNWULcgAJi4jIwARSnIVKC/fY8OsTcAnItyOrrxQC3IPJg/cF+E= =cYhB -----END PGP SIGNATURE-----