ghostscript-9.52-161.1<>,$aݥ3p9|+!ob,)vdR"gʞIt8A\!0͔wﷴ^5)^9:7d&h)䙐qր.zuq iqmet|y`t_}! \xSKZo(uʿbPE2Oӓхm›/4UjrxlLۚ:5P.K0oj_2l{k 7 e?ҕKBQٮ>L?d  LTXhl cww w |w "Xw w Dw wsww `g(8292:2>t?|@BFGwHwIwX Y@ Zl[x\w]`w^bc?defluwv@wwx wyp1z4DHqCghostscript9.52161.1The Ghostscript interpreter for PostScript and PDFGhostscript is a package of software that provides: An interpreter for the PostScript language, with the ability to convert PostScript language files to many raster formats, view them on displays, and print them on printers that don't have PostScript language capability built in. An interpreter for Portable Document Format (PDF) files, with the same abilities. The ability to convert PostScript language files to PDF (with some limitations) and vice versa. A set of C procedures (the Ghostscript library) that implement the graphics and filtering (data compression / decompression / conversion) capabilities that appear as primitive operations in the PostScript language and in PDF. For information how to use Ghostscript see /usr/share/ghostscript/9.52/doc/Use.htmaݥ3ibs-power9-118>CSUSE Linux Enterprise 15SUSE LLC AGPL-3.0-onlyhttps://www.suse.com/System/Librarieshttps://www.ghostscript.com/linuxppc64le/sbin/ldconfig /usr/sbin/update-alternatives \ --install /usr/bin/gs gs /usr/bin/gs.bin 15if test $1 -eq 0 ; then /usr/sbin/update-alternatives \ --remove gs /usr/bin/gs.bin fi^``a^^w 6E !0 x7np #E i>dtG G,xG&xwZas8C6J.(6Q"1F|.I, ;8 c: 9:0 @:K;4:_sss[ ! ut R S y a >=  04#0  Z \ & <=<  a' ID Vcs D \ i Q u m[) R 5 5& @ [ J 0W   . !-I_ / >> . /1P - CXI  ݊ v %mM 0  r : O pF ) K  *  ITrM1<Mp. I  9 I Zhm s,6 !E  T :^E6OaXZA.$A&+ A_<yBvpcz-^/$/ )m2lS0d9A!97KH V"Cb$<,} O ]p JLt WWE G 00Ѣ{*6M`O VbX  D cbJ)ycX W 33 `4\ 2(44(  dv]dt[[u[t[[t[l||+, N J^Hd+ G I  R\Y]c P J{/ZW1-.;-"W"!\0CzuVQjp8WX=oo[GKn[Iyc f b;(*pp ] u6   2XX  :AAAA큤A큤AAAA큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤aݥaݥ aݥ aݥaݥ&aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥaݥaݥ aݥ&aݥ&aݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥ aݥaݥaݥ aݥ aݥ aݥ aݥaݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥ aݥ aݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥaݥaݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥaݥaݥ aݥ aݥ aݥaݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥaݥaݥaݥaݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥaݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥ aݥaݥ'aݥaݥaݥaݥaݥaݥaݥ'aݥ'aݥ'aݥaݥaݥ'aݥaݥ'aݥ'aݥ'aݥ'aݥaݥaݥaݥaݥaݥaݥaݥaݥaݥaݥ'aݥ'aݥ'aݥaݥ.bin/etc/alternatives/gslibgs.so.9.52../ghostscript/9.52ps2ps.1.gzps2pdf.1.gzps2pdf.1.gzps2pdf.1.gzps2ps.1.gzgslp.1.gzgslp.1.gzgslp.1.gzgslp.1.gzps2pdf.1.gzps2pdf.1.gzps2pdf.1.gzArootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootghostscript-9.52-161.1.src.rpmconfig(ghostscript)ghostscriptghostscript(ppc-64)ghostscript-libraryghostscript_anygsgs_liblibgs.so.9()(64bit)libijs-0.35.so()(64bit)pstoraster @@@@@@@@@@@@@@@@@@@    /bin/sh/bin/sh/bin/sh/sbin/ldconfigconfig(ghostscript)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcups.so.2()(64bit)libcupsimage.so.2()(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.17)(64bit)libfontconfig.so.1()(64bit)libfreetype.so.6()(64bit)libgs.so.9()(64bit)libjpeg.so.8()(64bit)libjpeg.so.8(LIBJPEG_8.0)(64bit)libm.so.6()(64bit)libm.so.6(GLIBC_2.17)(64bit)libpng16.so.16()(64bit)libpng16.so.16(PNG16_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)libtiff.so.5()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)update-alternativesupdate-alternatives9.52-161.13.0.4-14.6.0-14.0-15.2-1ghostscript-x11ghostscript-x119.52-161.19.52-161.14.14.1aq@aTU@a;H`_^]M@]y@]y@]{]QT\\\@n@\&@[v[[Q@[Q@[{@ZZZ`@ZZH@Z@Y5Yo@Y1S@YtXXsXwoX@W@Wڍ@V@VVLh@V;DV3[VVV }@VU@U@U@U U jsmeix@suse.dewerner@suse.dejsmeix@suse.dewolfgang.frisch@suse.comjsmeix@suse.dejsmeix@suse.dejsmeix@suse.dewerner@suse.dewerner@suse.dewerner@suse.dewerner@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.destefan.bruens@rwth-aachen.denovell@mirell.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dedaniel.molkentin@suse.comjsmeix@suse.dejsmeix@suse.dejsmeix@suse.destefan.bruens@rwth-aachen.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.deschwab@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.dejsmeix@suse.de- CVE-2021-45944.patch fixes CVE-2021-45944 use-after-free in sampled_data_sample cf. https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-237.yaml (bsc#1194303) - CVE-2021-45949.patch fixes CVE-2021-45949 heap-based buffer overflow in sampled_data_finish cf. https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml (bsc#1194304)- Use update-alternatives to get the real ghostscript binary from /usr/bin/gs to /usr/bin/gs.bin and allow the gswrap package to use this with its wrapper script (jira#PM-3037)- CVE-2021-3781.patch fixes CVE-2021-3781 Trivial -dSAFER bypass cf. https://bugs.ghostscript.com/show_bug.cgi?id=704342 (bsc#1190381)- Hardening: link as position independent executable (bsc#1184123).- CVE-2020-15900.patch fixes CVE-2020-15900 Memory Corruption (SAFER Sandbox Breakout) cf. https://bugs.ghostscript.com/show_bug.cgi?id=702582 (bsc#1174415)- The version upgrade to 9.52 fixes in particular CVE-2020-12268: jbic2dec: heap-based buffer overflow in jbig2_image_compose (bsc#1170603) - Version upgrade to 9.52 Highlights in this release include: * The 9.52 release replaces the 9.51 release after a problem was reported with 9.51 which warranted the quick turnaround. Thus, like 9.51, 9.52 is primarily a maintenance release, consolidating the changes we introduced in 9.50. * IMPORTANT: We have forked LittleCMS2 into LittleCMS2mt (the "mt" indicating "multi-thread"). LCMS2 is not thread-safe, and cannot be made thread-safe without breaking the ABI. Our fork will be thread-safe and include performance enhancements (these changes have all been offered and rejected upstream). We will maintain compatibility between Ghostscript and LCMS2 for a time, but not in perpetuity. If there is sufficient interest, our fork will be available as its own package separately from Ghostscript (and MuPDF). * The usual round of bug fixes, compatibility changes, and incremental improvements. Incompatible changes: * New option -dALLOWPSTRANSPARENCY: The transparency compositor (and related features), whilst we are improving it, remains sensitive to being driven correctly, and incorrect use can have unexpected/undefined results. Hence, as part of improving security, we limited access to these operators, originally using the -dSAFER feature. As we made "SAFER" the default mode, that became unacceptable, hence the new option -dALLOWPSTRANSPARENCY which enables access to the operators, cf. https://www.ghostscript.com/doc/9.52/Use.htm#ALLOWPSTRANSPARENCY For a release summary see: https://www.ghostscript.com/doc/9.52/News.htm For details see the News.htm and History9.htm files. - Version upgrade to 9.51 Highlights in this release include: * 9.51 is primarily a maintainance release, consolidating the changes we introduced in 9.50. * We have continued our work on code hygiene for this release, with a focus on the static analysis tool Coverity (from Synopsys, Inc) and we are now maintaining a policy of zero Coverity issues in the Ghostscript/GhostPDL source base. * IMPORTANT: In consultation with a representative of OpenPrinting (http://www.openprinting.org/) it is our intention to deprecate and, in the not distant future, remove the OpenPrinting Vector/Raster Printer Drivers (that is, the opvp and oprp devices). If you rely on either of these devices, please get in touch with us (i.e. Ghostscript upstream), so we can discuss your use case, and revise our plans accordingly. * We (i.e. Ghostscript upstream) are in the process of forking LittleCMS, cf. the other release notes entries below. * The usual round of bug fixes, compatibility changes, and incremental improvements. For a release summary see: https://www.ghostscript.com/doc/9.51/News.htm For details see the News.htm and History9.htm files. - Version upgrade to 9.50 Highlights in this release include: * The change to version 9.50 follows recognition of the extent and importance of the file access control redesign/reimplementation outlined below. * The file access control capability (enable with -dSAFER) has been completely rewritten, with a ground-up rethink of the design. For more details, see: "SAFER" at https://www.ghostscript.com/doc/9.50/Use.htm#Safer * It is important to note that -dSAFER now only enables the file access controls, and no longer applies restrictions to standard Postscript functionality (specifically, restrictions on setpagedevice). If your application relies on these Postscript restrictions, see "OLDSAFER" at https://www.ghostscript.com/doc/9.50/Use.htm#OldSafer and please get in touch, as we do plan to remove those Postscript restrictions unless we have reason not to. IMPORTANT: File access controls are now enabled by default. In order to run Ghostscript without these controls, see "NOSAFER" at https://www.ghostscript.com/doc/9.50/Use.htm#NoSafer * We (i.e. Ghostscript upstream) are in the process of forking LittleCMS, cf. the other release notes entries below. * The usual round of bug fixes, compatibility changes, and incremental improvements. Incompatible changes: * There are a couple of subtle incompatibilities between the old and new SAFER implementations. Firstly, as mentioned above, SAFER now leaves standard Postcript functionality unchanged (except for the file access limitations). Secondly, the interaction with save/restore operations, see "SAFER" at https://www.ghostscript.com/doc/9.50/Use.htm#Safer * The following is not strictly speaking new to 9.50, as not much has changed since 9.27 in this area, but for those who don't upgrade with every release: The process of "tidying" the Postscript name space should have removed only non-standard and undocumented operators. Nevertheless, it is possible that any integrations or utilities that rely on those non-standard and undocumented operators may stop working, or may change behaviour. If you encounter such a case, please contact us (i.e. Ghostscript upstream, either the #ghostscript IRC channel or the gs-devel mailing list would be best), and we'll work with you to either find an alternative solution or return the previous functionality, if there is genuinely no other option. One case we know this has occurred is GSView 5 (and earlier). GSView 5 support for PDF files relied upon internal use only features which are no longer available. GSView 5 will still work as previously for Postscript files. For PDF files, users are encouraged to look at MuPDF https://www.mupdf.com/ For a release summary see: https://www.ghostscript.com/doc/9.50/News.htm For details see the News.htm and History9.htm files. - CVE-2019-10216.patch CVE-2019-14869.patch gs-CVE-2019-14811-885444fc.patch gs-CVE-2019-14817-cd1b1cac.patch openjpeg4gs-CVE-2018-6616-8ee33522.patch are fixed in the version 9.52 upstream sources.- CVE-2019-14869.patch contains commit from Ghostscript upstream https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=485904772c5f to fix CVE-2019-14869 "-dSAFER escape in .charkeys" (bsc#1156275)- Port latest ghostscript 9.27 from factory including latest security patches to SLES15/SLES12 * Port patch CVE-2019-10216.patch to 9.27 which is the orignal upstream commit now * Drop patch CVE-2019-3838.patch as now part of 9.27- Add patch gs-CVE-2019-14811-885444fc.patch to fix bsc#1146882 for CVE-2019-14811,CVE-2019-14812,CVE-2019-14813 - Add patch gs-CVE-2019-14817-cd1b1cac.patch to fix bsc#1146884 for CVE-2019-14817- Add patch openjpeg4gs-CVE-2018-6616-8ee33522.patch to fix bsc#1140359 for CVE-2019-12973- CVE-2019-10216.patch fixes CVE-2019-10216 forceput/superexec in .buildfont1 is still accessible https://bugzilla.suse.com/show_bug.cgi?id=1144621 bsc#1144621 https://bugs.ghostscript.com/show_bug.cgi?id=701394- Version upgrade to 9.27 Highlights in this release include: * We (i.e. Ghostscript upstream) have extensively cleaned up the Postscript name space: removing access to internal and/or undocumented Postscript operators, procedures and data. This has benefits for security and maintainability. Incompatible changes: The process of "tidying" the Postscript name space should have removed only non-standard and undocumented operators. Nevertheless, it is possible that any integrations or utilities that rely on those non-standard and undocumented operators may stop working, or may change behaviour. If you encounter such a case, please contact us (i.e. Ghostscript upstream) - (either the #ghostscript IRC channel, or the gs-devel mailing list would be best), and we'll work with you to either find an alternative solution. * Fontmap can now reference invidual fonts in a TrueType Collection for font subsitution. Previously, a Fontmap entry could only reference a TrueType collection and use the default (first) font. Now, the Fontmap syntax allows for specifying a specific index in a TTC. See the comments at the top of (the default) Fontmap.GS for details. * The usual round of bug fixes, compatibility changes, and incremental improvements. IMPORTANT: It is our intention, within the next 12 months (ideally sooner, in time for the next release) to make SAFER the default mode of operation. For many users this will have no effect, since they use SAFER explicitly, but some niche uses which rely on SAFER being disabled may need to start explicitly adding the "-dNOSAFER" option. IMPORTANT: We (i.e. Ghostscript upstream) are in the process of forking LittleCMS. LCMS2 is not thread safe, and cannot be made thread safe without breaking the ABI. Our fork will be thread safe, and include performance enhancements (these changes have all be been offered and rejected upstream). We will maintain compatibility between Ghostscript and LCMS2 for a time, but not in perpetuity. Our fork will be available as its own package separately from Ghostscript (and MuPDF). For a release summary see: http://www.ghostscript.com/doc/9.27/News.htm For details see the News.htm and History9.htm files. The Ghostscript 9.27 release should fix (cf. the entry below dated 'Fri Sep 14 10:47:33 CEST 2018' what "should fix" means) in particular those security issues: * CVE-2019-3838 forceput in DefineResource is still accessible https://bugzilla.suse.com/show_bug.cgi?id=1129186 bsc#1129186 https://bugs.ghostscript.com/show_bug.cgi?id=700576 * CVE-2019-3835: superexec operator is available https://bugzilla.suse.com/show_bug.cgi?id=1129180 bsc#1129180 https://bugs.ghostscript.com/show_bug.cgi?id=700585- CVE-2019-3838.patch fixes CVE-2019-3838 forceput in DefineResource is still accessible https://bugzilla.suse.com/show_bug.cgi?id=1129186 bsc#1129186 https://bugs.ghostscript.com/show_bug.cgi?id=700576- Version upgrade to 9.26a The version 9.26a is a special security bugfix version to fix * CVE-2019-6116: subroutines within pseudo-operators must themselves be pseudo-operators https://bugs.ghostscript.com/show_bug.cgi?id=700317 https://bugzilla.suse.com/show_bug.cgi?id=1122319 bsc#1122319- Version upgrade to 9.26 Highlights in this release include: * Security issues have been the primary focus of this release, including solving several (well publicised) real and potential exploits. Thanks to Man Yue Mo of Semmle Security Research Team, Jens Mueller of Ruhr-Universitaet Bochum and Tavis Ormandy of Google's Project Zero for their help to identify specific security issues. PLEASE NOTE: We (i.e. Ghostscript upstream) strongly urge users to upgrade to this latest release to avoid these issues. * The usual round of bug fixes, compatibility changes, and incremental improvements. For a release summary see: http://www.ghostscript.com/doc/9.26/News.htm For details see the News.htm and History9.htm files. The Ghostscript 9.26 release should fix (cf. the entry below dated 'Fri Sep 14 10:47:33 CEST 2018' what "should fix" means) in particular those security issues (bsc#1117331) * CVE-2018-19475: psi/zdevice2.c allows attackers to bypass intended access restrictions https://bugs.ghostscript.com/show_bug.cgi?id=700153 https://bugzilla.suse.com/show_bug.cgi?id=1117327 bsc#1117327 * CVE-2018-19476: psi/zicc.c allows attackers to bypass intended access restrictions because of a setcolorspace type confusion https://bugs.ghostscript.com/show_bug.cgi?id=700169 https://bugzilla.suse.com/show_bug.cgi?id=1117313 bsc#1117313 * CVE-2018-19477: psi/zfjbig2.c allows attackers to bypass intended access restrictions because of a JBIG2Decode type confusion https://bugs.ghostscript.com/show_bug.cgi?id=700168 https://bugzilla.suse.com/show_bug.cgi?id=1117274 bsc#1117274 * CVE-2018-19409: LockSafetyParams is not checked correctly if another device is used https://bugs.ghostscript.com/show_bug.cgi?id=700176 https://bugzilla.suse.com/show_bug.cgi?id=1117022 bsc#1117022 and those security issues * CVE-2018-18284: 1Policy operator gives access to .forceput https://bugs.ghostscript.com/show_bug.cgi?id=69963 https://bugzilla.suse.com/show_bug.cgi?id=1112229 bsc#1112229 * CVE-2018-18073: saved execution stacks can leak operator arrays https://bugs.ghostscript.com/show_bug.cgi?id=699927 https://bugzilla.suse.com/show_bug.cgi?id=1111480 bsc#1111480 * CVE-2018-17961: bypassing executeonly to escape -dSAFER sandbox https://bugs.ghostscript.com/show_bug.cgi?id=699816 https://bugzilla.suse.com/show_bug.cgi?id=1111479 bsc#1111479 * CVE-2018-17183: remote attackers could be able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code https://bugs.ghostscript.com/show_bug.cgi?id=699708 https://bugzilla.suse.com/show_bug.cgi?id=1109105 bsc#1109105- Version upgrade to 9.26rc1 (first release candidate for 9.26). Highlights in this release include: * Purely security and a few bug fixes, there are no new features, and no API changes to report.- Version upgrade to 9.25 For the highlights in this release see the highlights in the 9.25rc1 first release candidate for 9.25 entry below. PLEASE NOTE: We (i.e. Ghostscript upstream) strongly urge users to upgrade to this latest release to avoid these issues. For a release summary see: http://www.ghostscript.com/doc/9.25/News.htm For details see the News.htm and History9.htm files. The Ghostscript 9.25 release should fix (see below) in particular those security issues: * CVE-2018-15909: shading_param incomplete type checking https://bugs.ghostscript.com/show_bug.cgi?id=699660 https://bugzilla.suse.com/show_bug.cgi?id=1106172 bsc#1106172 * CVE-2018-15908: .tempfile file permission issues https://bugs.ghostscript.com/show_bug.cgi?id=699657 https://bugzilla.suse.com/show_bug.cgi?id=1106171 bsc#1106171 * CVE-2018-15910: LockDistillerParams type confusion https://bugs.ghostscript.com/show_bug.cgi?id=699656 https://bugzilla.suse.com/show_bug.cgi?id=1106173 bsc#1106173 * CVE-2018-15911: uninitialized memory access in the aesdecode https://bugs.ghostscript.com/show_bug.cgi?id=699665 https://bugzilla.suse.com/show_bug.cgi?id=1106195 bsc#1106195 * CVE-2018-16513: setcolor missing type check https://bugs.ghostscript.com/show_bug.cgi?id=699655 https://bugzilla.suse.com/show_bug.cgi?id=1107412 bsc#1107412 * CVE-2018-16509: /invalidaccess bypass after failed restore https://bugs.ghostscript.com/show_bug.cgi?id=699654 https://bugzilla.suse.com/show_bug.cgi?id=1107410 bsc#1107410 * CVE-2018-16510: Incorrect exec stack handling in the "CS" and "SC" PDF primitives https://bugs.ghostscript.com/show_bug.cgi?id=699671 https://bugzilla.suse.com/show_bug.cgi?id=1107411 bsc#1107411 * CVE-2018-16542: .definemodifiedfont memory corruption if /typecheck is handled https://bugs.ghostscript.com/show_bug.cgi?id=699668 https://bugzilla.suse.com/show_bug.cgi?id=1107413 bsc#1107413 * CVE-2018-16541 incorrect free logic in pagedevice replacement https://bugs.ghostscript.com/show_bug.cgi?id=699664 https://bugzilla.suse.com/show_bug.cgi?id=1107421 bsc#1107421 * CVE-2018-16540 use-after-free in copydevice handling https://bugs.ghostscript.com/show_bug.cgi?id=699661 https://bugzilla.suse.com/show_bug.cgi?id=1107420 bsc#1107420 * CVE-2018-16539: incorrect access checking in temp file handling to disclose contents of files https://bugs.ghostscript.com/show_bug.cgi?id=699658 https://bugzilla.suse.com/show_bug.cgi?id=1107422 bsc#1107422 * CVE-2018-16543: gssetresolution and gsgetresolution allow for unspecified impact https://bugs.ghostscript.com/show_bug.cgi?id=699670 https://bugzilla.suse.com/show_bug.cgi?id=1107423 bsc#1107423 * CVE-2018-16511: type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact https://bugs.ghostscript.com/show_bug.cgi?id=699659 https://bugzilla.suse.com/show_bug.cgi?id=1107426 bsc#1107426 * CVE-2018-16585 .setdistillerkeys PostScript command is accepted even though it is not intended for use https://bugzilla.suse.com/show_bug.cgi?id=1107581 bsc#1107581 * CVE-2018-16802: Incorrect"restoration of privilege" checking when running out of stack during exceptionhandling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509 https://bugs.ghostscript.com/show_bug.cgi?id=699714 https://bugs.ghostscript.com/show_bug.cgi?id=699718 https://bugzilla.suse.com/show_bug.cgi?id=1108027 bnc#1108027 Regarding what the above "should fix" means: PostScript is a general purpose Turing-complete programming language (cf. https://en.wikipedia.org/wiki/PostScript) that supports in particular file access on the system disk. When Ghostscript processes PostScript it runs a PostScript program as the user who runs Ghostscript. When Ghostscript processes an arbitrary PostScript file, the user who runs Ghostscript runs an arbitrary program which can do anything on the system where Ghostscript runs that this user is allowed to do on that system. To make it safer when Ghostscript runs a PostScript program the Ghostscript command line option '-dSAFER' disables certain file access functionality, for details see /usr/share/doc/ghostscript/9.25/Use.htm Its name 'SAFER' says everything: It makes it 'safer' to let Ghostscript run a PostScript program, but it does not make it completely safe. In theory software is safe against misuse (i.e. has no bugs). In practice there is an endless sequence of various kind of security issues (i.e. software can be misused to do more than what is intended) that get fixed issue by issue ad infinitum. In the end all that means: In practice the user who runs Ghostscript must not let it process arbitrary PostScript files from untrusted origin. In particular Ghostscript is usually run when printing documents (with the '-dSAFER' option set), see the part about "It is crucial to limit access to CUPS to trusted users" in https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings- Version upgrade to 9.25rc1 (first release candidate for 9.25). Highlights in this release include: * This release fixes problems with argument handling, some unintended results of the security fixes to the SAFER file access restrictions (specifically accessing ICC profile files), and some additional security issues over the 9.24 release. * Security issues have been the primary focus of this release, including solving several (well publicised) real and potential exploits. PLEASE NOTE: We (i.e. Ghostscript upstream) strongly urge users to upgrade to this latest release to avoid these issues. * Avoid that ps2epsi fails with 'Error: /undefined in --setpagedevice--' Recent changes required to harden SAFER mode mean that it is no longer possible to run ps2epsi in SAFER mode, because it relies upon unsafe Ghostscript non-standard extension operators. Removing SAFER and DELAYSAFER, and the code to reset SAFER, allow ps2epsi to run as well as it ever did (ie badly). This program (i.e. ps2epsi) should now be considered unsafe, you should not use it on untrusted PostScript programs. Likely we (i.e. Ghostscript upstream) will deprecate and remove this program in future. For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing- Version upgrade to 9.24 Highlights in this release include: * Security issues have been the primary focus of this release, including solving several (well publicised) real and potential exploits. PLEASE NOTE: We (i.e. Ghostscript upstream) strongly urge users to upgrade to this latest release to avoid these issues. * As well as Ghostscript itself, jbig2dec has had a significant amount of work improving its robustness in the face of out specification files. * IMPORTANT: We (i.e. Ghostscript upstream) are in the process of forking LittleCMS. LCMS2 is not thread safe, and cannot be made thread safe without breaking the ABI. Our fork will be thread safe, and include performance enhancements (these changes have all be been offered and rejected upstream). We will maintain compatibility between Ghostscript and LCMS2 for a time, but not in perpetuity. Our fork will be available as its own package separately from Ghostscript (and MuPDF). * The usual round of bug fixes, compatibility changes, and incremental improvements. For a release summary see: http://www.ghostscript.com/doc/9.24/News.htm For details see the News.htm and History9.htm files. - fix_ln_docdir_gsdatadir.patch is no longer needed because the issue is fixed in the upstream sources. - CVE-2018-10194.patch is no longer needed because the issue is fixed in the upstream sources.- CVE-2018-10194.patch fixes stack-based buffer overflow in gdevpdts.c (bsc#1090099), see https://bugs.ghostscript.com/show_bug.cgi?id=699255 and http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=39b1e54b2968620723bf32e96764c88797714879- Version upgrade to 9.23 Highlights in this release include: * Ghostscript now has a family of 'pdfimage' devices (pdfimage8, pdfimage24 and pdfimage32) which produce rendered output wrapped up as an image in a PDF. Additionally, there is a 'pclm' device which produces PCLm format output. * There is now a ColorAccuracy parameter allowing the user to decide between speed or accuracy in ICC color transforms. * JPEG Passthrough: devices which support it can now receive the 'raw' JPEG stream from the interpreter. The main use of this is the pdfwrite/ps2write family of devices that can now take JPEG streams from the input file(s) and write them unchanged to the output (thus avoiding additional quantization effects). * PDF transparency performance improvements * IMPORTANT: We (i.e. Ghostscript upstream) are in the process of forking LittleCMS. LCMS2 is not thread safe, and cannot be made thread safe without breaking the ABI. Our fork will be thread safe, and include performance enhancements (these changes have all be been offered and rejected upstream). We will maintain compatibility between Ghostscript and LCMS2 for a time, but not in perpetuity. Our fork will be available as its own package separately from Ghostscript (and MuPDF). * We have continued the focus on code hygiene in this release cleaning up security issues, ignored return values, and compiler warnings. * The usual round of bug fixes, compatibility changes, and incremental improvements. Incompatible changes * The planned device API tidy has, unfortunately, been indefinitely postponed, until appropriate resources are available. For a release summary see: http://www.ghostscript.com/doc/9.23/News.htm For details see the News.htm and History9.htm files. See also the entries below since "Version upgrade to 9.22" (boo#1082896 and boo#1074266).- For now use lcms2 from SUSE because that is what currently Ghostscript upstream recommends according to https://ghostscript.com/pipermail/gs-devel/2018-March/010061.html because since Ghostscript 9.23rc1 there is no longer lcms2 in Ghostscript but now it is lcms2art which is the beginning of a lcms2 fork, see News.htm that reads in particular "LCMS2 is not thread safe ... Our fork will be thread safe ... We will maintain compatibility between Ghostscript and LCMS2 for a time, but not in perpetuity", see also https://bugzilla.opensuse.org/show_bug.cgi?id=1082896#c14 - On SLE11 and on SLE12-SP1 there is liblcms2-2-2.5 which is too old so that configure fails there with configure: error: lcms2 not found, or too old but there is no configure option to build it without lcms2 so that for SLE11 and SLE12-SP1 it is built with the lcms2art in Ghostscript. - ppc64le-support.patch is no longer needed because it only contained a fix for lcms2art/include/lcms2art.h in Ghostscript but currently lcms2 from SUSE is used instead (see above). - Do no longer require any fonts packages in particular neither require ghostscript-fonts-std because the PostScript Base35 fonts are provided by Ghostscript (in 'Resource') nor require ghostscript-fonts-other (provides Bitream Charter, Adobe Utopia, URW Antiqua, URW Grotesq and Hershey fonts where all but the last are also provided by texlive--fonts) and those fonts are not required for PostScript compliance, see https://bugzilla.opensuse.org/show_bug.cgi?id=1082896#c13- Version upgrade to 9.23rc1 (first release candidate for 9.23). For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing - Adapted ppc64le-support.patch: In Ghostscript 9.23 there is now lcms2art/include/lcms2art.h (instead of lcms2/include/lcms2.h). - ghostscript-fix-debug-use.patch is no longer needed because the issue is fixed in the upstream sources. - fix_ln_docdir_gsdatadir.patch avoids "base/unixinst.mak:162: recipe for target 'install-doc' failed" - Adapted spec file to the new Ghostscript upstream documentation directory /usr/share/doc/ghostscript/9.23/- Use -p /sbin/ldconfig instead of shell post(un) scriptlet, drop explicit Prereq for ldconfig - Use shared libgs library for gs binary instead of static linked version - Use --disable-compile-inits, to allow unbundling of Resource files - Remove --disable-omni switch, has been removed in GS 9.20 - Keep patch ordering in full/mini consistent - Remove patch backup files to avoid packaging- Add ghostscript-fix-debug-use.patch from upstream to fix broken printing with some drivers (especially Dell Printers) from https://bugs.ghostscript.com/show_bug.cgi?id=698837 - Fix build for SLE targets- Version upgrade to 9.22. For details see the News.htm and History9.htm files. Highlights in this release include: * Ghostscript can now consume and produce (via the pdfwrite device) PDF 2.0 compliant files. * The main focus of this release has been security and code cleanliness. Hence many AddressSanitizer, Valgrind and Coverity issues have been addressed. * The usual round of bug fixes, compatibility changes, and incremental improvements. Incompatible changes * The planned device API tidy (still!) did not happen for this release, due to time pressures, but we still intend to undertake the following: We plan to somewhat tidy up the device API. We intend to remove deprecated device procs (methods/function pointers) and change the device API so every device proc takes a graphics state parameter (rather than the current scheme where only a very few procs take an imager state parameter). This should serve as notice to anyone maintaining a Ghostscript device outside the canonical source tree that you may (probably will) need to update your device(s) when these changes happen. Devices using only the non-deprecated procs should be trivial to update. - Up to 9.22rc1 it "just built" for all openSUSE versions but since 9.22rc2 the libijs part does no longer buid for any released openSUSE version where if fails with messages like libtool: Version mismatch error. This is libtool 2.4.6 Debian-2.4.6-2, but the definition of this LT_INIT comes from libtool 2.4.2. You should recreate aclocal.m4 with macros from libtool 2.4.6 Debian-2.4.6-2 and run autoconf again. Makefile: recipe for target 'ijs.lo' failed so that currently it only builds for Tumbleweed/Factory. Presumably it is not too complicated to make it build again also for released openSUSE versions but currently I have less than zero energy to fix such "latest breaking changes" so that for now Ghostscript 9.22 is only provided for openSUSE Tumbleweed/Factory and the upcoming SLE15/Leap15.- Version upgrade to 9.22rc2 (second release candidate for 9.22). For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing- Version upgrade to 9.22rc1 (first release candidate for 9.22). For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing - Since Ghostscript 9.22rc1 font2c and wftopfa are removed. - CVE-2017-5951.patch CVE-2017-7207.patch CVE-2017-8291.patch and CVE-2017-9216.patch are fixed in the version 9.22rc1 upstream sources.- CVE-2017-7207.patch fixes a NULL pointer dereference in mem_get_bits_rectangle see https://bugs.ghostscript.com/show_bug.cgi?id=697676 (bsc#1030263) - CVE-2017-9216.patch fixes a NULL pointer dereference in jbig2_huffman_get see https://bugs.ghostscript.com/show_bug.cgi?id=697934 (bsc#1040643)- CVE-2017-8291.patch fixes a type confusion in .rsdparams and .eqproc see https://bugs.ghostscript.com/show_bug.cgi?id=697808 and https://bugs.ghostscript.com/show_bug.cgi?id=697799 (bsc#1036453).- CVE-2016-10317 (bsc#1032230) heap buffer overflow in fill_threshhold_buffer() is not yet fixed because there is no fix available at https://bugs.ghostscript.com/show_bug.cgi?id=697459 - CVE-2016-10219 (bsc#1032138) divide by zero in intersect() https://bugs.ghostscript.com/show_bug.cgi?id=697453 is fixed in the version 9.21 upstream sources - CVE-2016-10218 (bsc#1032135) null pointer dereference in pdf14_pop_transparency_group() https://bugs.ghostscript.com/show_bug.cgi?id=697444 is fixed in the version 9.21 upstream sources. - CVE-2016-10217 (bsc#1032130) use-after-free in pdf14_cleanup_parent_color_profiles() that is related to pdf14_open() in base/gdevp14.c https://bugs.ghostscript.com/show_bug.cgi?id=697456 is fixed in the version 9.21 upstream sources. - CVE-2016-10220 (bsc#1032120) null pointer dereference in gx_device_finalize() that is related to gs_makewordimagedevice() in base/gsdevmem.c https://bugs.ghostscript.com/show_bug.cgi?id=697450 is fixed in the version 9.21 upstream sources. - CVE-2017-5951.patch fixes null pointer dereference in ref_stack_index() that is related to mem_get_bits_rectangle() in base/gdevmem.c https://bugs.ghostscript.com/show_bug.cgi?id=697548 (bsc#1032114)- Version upgrade to 9.21. For details see the News.htm and History9.htm files. Highlights in this release include: * pdfwrite now preserves annotations from input PDFs (where possible). * The GhostXPS interpreter now provides the pdfwrite device with the data it requires to emit a ToUnicode CMap: thus allowing fully searchable PDFs to be created from XPS input (in the vast majority of cases). * Ghostscript now allows the default color space for PDF transparency blends. * The Ghostscript/GhostPDL configure script now has much better/fuller support for cross compiling. * The tiffscaled and tiffscaled4 devices can now use ETS (Even Tone Screening) * The toolbin/pdf_info.ps utility can now emit the PDF XML metadata. * Ghostscript has a new scan converter available (currently optional, but will become the default in a near future release). It can be enabled by using the command line option: '-dSCANCONVERTERTYPE=2'. This new implementation provides vastly improved performance with large and complex paths. * The usual round of bug fixes, compatibility changes, and incremental improvements. Incompatible changes: * The planned device API tidy (still!) did not happen for this release, due to time pressures, but we still intend to undertake the following: We plan to somewhat tidy up the device API. We intend to remove deprecated device procs (methods/function pointers) and change the device API so every device proc takes a graphics state parameter (rather than the current scheme where only a very few procs take an imager state parameter). This should serve as notice to anyone maintaining a Ghostscript device outside the canonical source tree that you may (probably will) need to update your device(s) when these changes happen. Devices using only the non-deprecated procs should be trivial to update. - CVE-2016-7976.patch and CVE-2016-7977.patch and CVE-2016-7978.patch and CVE-2016-7979.patch and CVE-2016-8602.patch are no longer needed because those issues are fixed in the upstream sources. - 0001-mkromfs-make-build-reproducible-use-buildtime-from-S.patch and 0002-mkromfs-sort-gp_enumerate_files-output-for-determini.patch are no longer needed because both are included in the upstream sources, see the upstream issue https://bugs.ghostscript.com/show_bug.cgi?id=697484 - Again use the zlib sources from Ghostscript upstream and disable remove-zlib-h-dependency.patch because Ghostscript 9.21 does no longer build this way, cf. the entry below dated "Wed Nov 18 11:46:58 UTC 2015"- Set SOURCE_DATE_EPOCH based on changelog head - Add 0001-mkromfs-make-build-reproducible-use-buildtime-from-S.patch * Use SOURCE_DATE_EPOCH for mkromfs output for reproducible build - Add 0002-mkromfs-sort-gp_enumerate_files-output-for-determini.patch * Sort ROM contents for deterministic output- CVE-2013-5653 (getenv and filenameforall ignore -dSAFER) is fixed in the Ghostscript 9.20 upstream sources see http://bugs.ghostscript.com/show_bug.cgi?id=694724 (bsc#1001951). - CVE-2016-7976.patch fixes that various userparams allow %pipe% in paths, allowing remote shell command execution see http://bugs.ghostscript.com/show_bug.cgi?id=697178 (bsc#1001951). - CVE-2016-7977.patch fixes that .libfile doesn't check PermitFileReading array, allowing remote file disclosure see http://bugs.ghostscript.com/show_bug.cgi?id=697169 (bsc#1001951). - CVE-2016-7978.patch fixes that reference leak in .setdevice allows use-after-free and remote code execution see http://bugs.ghostscript.com/show_bug.cgi?id=697179 (bsc#1001951). - CVE-2016-7979.patch fixes that type confusion in .initialize_dsc_parser allows remote code execution see http://bugs.ghostscript.com/show_bug.cgi?id=697190 (bsc#1001951). - CVE-2016-8602.patch fixes a NULL dereference in .sethalftone5 see http://bugs.ghostscript.com/show_bug.cgi?id=697203 (bsc#1004237).- Version upgrade to 9.20. Purely a maintenance release. For details see the News.htm and History9.htm files. Highlights in this release include: * The usual round of bug fixes, compatibility changes, and incremental improvements. Incompatible changes: * The planned device API tidy did not happen for this release, due to time pressures, but we still intend to undertake the following: We plan to somewhat tidy up the device API. We intend to remove deprecated device procs (methods/function pointers) and change the device API so every device proc takes a graphics state parameter (rather than the current scheme where only a very few procs take an imager state parameter). This should serve as notice to anyone maintaining a Ghostscript device outside the canonical source tree that you may (probably will) need to update your device(s) when these changes happen. Devices using only the non-deprecated procs should be trivial to update.- Version upgrade to 9.20rc1 (first release candidate for 9.20). For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing- Version upgrade to 9.19. Mainly a maintenance release. For details see the News.htm and History9.htm files. Highlights in this release include: * Metadata pdfmark is now implemented. This allows the user to specify an XMP stream which will be written to the Catalog of the PDF file. A new pdfmark 'Ext_Metadata' has been defined. This takes a string parameter which contains XML to be add to the XMP normally created by pdfwrite. See "pdfwrite pdfmark extensions" for more information. * An experimental, rudimentary raster trapping implementation has been added to the Ghostscript graphics library. See "Trapping" for details. Incompatible changes: * (Minor) API change: copy_alpha now supports 8 bit depth (as well as the previous 2 and 4). * The gs man pages are woefully out of date and basically unmaintained. With the release following 9.19, we intend to replace their contents with a very limited summary of (unlikely to ever change aspects of) calling Ghostscript, and a pointer to the (maintained) HTML documentation. That is, unless a volunteer is willing to update, and commit to maintaining the man pages. * ijs-config is no longer provided Planned incompatible changes: * We plan (ideally for the release following 9.19) to somewhat tidy up the device API. We plan to remove deprecated device procs (methods/function pointers). We also intend to merge the imager state and graphics state (thus eliminating the imager state), and change the device API so every device proc takes a graphics state parameter (rather than the current scheme where only a very few procs take an imager state parameter). This should serve as notice to anyone maintaining a Ghostscript device outside the canonical source tree that you may (probably will) need to update your device(s) when these changes happen. Devices using only the non-deprecated procs should be trivial to update. - fix_make_install.patch fixes and add_brackets_for_old_autoconf.patch are no longer needed because both issues are fixed in the upstream sources.- Version upgrade to 9.19rc1 (first release candidate for 9.19). For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing - ijs-config is no longer provided - fix_make_install.patch fixes an install error and add_brackets_for_old_autoconf.patch fixes an autoconf error see http://bugs.ghostscript.com/show_bug.cgi?id=696665 - fix_ijs_and_x11_for_FirstPage_and_LastPage.patch is no longer needed because it is fixed in the upstream sources. - install_gserrors.h.patch is no longer needed because it is fixed in the upstream sources.- Do not use library sources for freetype jpeg libpng tiff zlib from the Ghostscript upstream tarball because we prefer to use for long-established standard libraries the ones from SUSE in particular to automatically get SUSE security updates for standard libraries. In contrast we use e.g. lcms2 from the Ghostscript upstream tarball because this one is specially modified to work with Ghostscript so that we cannot use lcms2 from SUSE. - remove-zlib-h-dependency.patch removes dependency on zlib/zlib.h in makefiles as we do not use the zlib sources from the Ghostscript upstream tarball.- An incompatible change appeared when building other software with Ghostscript 9.18. Since version 9.18 Ghostscript does no longer provide e_ (e.g. e_NeedInput) in its header files (gserrors.h and ierrors.h). When building other software with Ghostscript 9.18 gs_error_ (e.g. gs_error_NeedInput) must be used, see boo#953149 and http://bugs.ghostscript.com/show_bug.cgi?id=696317- install_gserrors.h.patch installs gserrors.h to fix http://bugs.ghostscript.com/show_bug.cgi?id=696301 because without gserrors.h several other packages fail to build (in particular texlive, libspectre, gimp,...).- fix_ijs_and_x11_for_FirstPage_and_LastPage.patch fixes the Ghostscript device ijs and the x11* devices so that they also work when -dFirstPage/-dLastPage is used, see http://bugs.ghostscript.com/show_bug.cgi?id=696246- Version upgrade to 9.18. A maintenance release. There are no recorded incompatible changes (as of this writing). Highlights in this release include: * A substantial revision of the build system and GhostPDL directory structure. Ghostscript-only users should not be affected by this change. * A new method of internally inserting devices into the device chain has been developed, named "device subclassing". This allows suitably written devices to be more easily and consistently as "filter" devices. The first fruit of this is a new implementation of the "-dFirstPage"/"-dLastPage" feature which functions a device filter in the Ghostscript graphics library, meaning it works consistently with all input languages. * Plus the usual round of bug fixes, compatibility changes, and incremental improvements. See http://www.ghostscript.com/doc/9.18/News.htm For details see the News.htm and History9.htm files.- Version upgrade to 9.18rc2 (second release candidate for 9.18). For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing - assign_pointer_not_value_in_gximono.c.patch is no longer needed because it is fixed in the upstream sources.- Version upgrade to 9.18rc1 (first release candidate for 9.18). For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing - CVE-2015-3228.patch is no longer needed because it is fixed in the upstream sources. - assign_pointer_not_value_in_gximono.c.patch attempts to fix a "assignment makes pointer from integer without a cast" compiler warning by assigning the pointer and not the integer value. - Removed --disable-compile-inits from configure, see http://bugs.ghostscript.com/show_bug.cgi?id=696223 and "Precompiled run-time data" in /usr/share/ghostscript/9.18/doc/Make.htm- CVE-2015-3228.patch fixes out of bound read/write cause by integer overflow in gsmalloc.c (boo#939342).- Version upgrade to 9.16. Primarily a maintenance release. There are no recorded incompatible changes (as of this writing). Highlights in this release include: * "LockColorants" command line option for tiffsep and psdcmyk devices. * Improved high level devices handling of Forms. See http://www.ghostscript.com/doc/9.16/News.htm For details see the News.htm and History9.htm files. - fix.including.pread.pwrite.pthread_mutexattr_settype.diff is no longer needed because it is fixed in the upstream sources.- fix.including.pread.pwrite.pthread_mutexattr_settype.diff fixes on SLE11 implicit declaration of function warnings for 'pread' 'pwrite' 'pthread_mutexattr_settype' see http://bugs.ghostscript.com/show_bug.cgi?id=695882 - ppc64le-support.patch is a remainder of the previous patch now the hunk for LCMS (lcms/include/lcms.h) is removed because LCMS 1.x is removed since Ghostscript 9.16 but the hunk for LCMS2 (lcms2/include/lcms2.h) is still needed see http://bugs.ghostscript.com/show_bug.cgi?id=695544- Version upgrade to 9.16rc2 (second release candidate for 9.16). For details see the News.htm and History9.htm files. Regarding installing packages (in particular release candidates) from the openSUSE build service development project "Printing" see https://build.opensuse.org/project/show/Printing- For SLE12 build it with traditional CUPS 1.5.4 to ensure it works on SLE12 both with CUPS 1.7.5 and CUPS 1.5.4./bin/sh/bin/sh/sbin/ldconfigghostscript-libraryghostscript-libraryghostscript-miniibs-power9-11 1641915699 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxy9.52-161.19.52-161.19.52-161.19.529.529.52            gsdvipdfeps2epsgsgs.bingsbjgsdjgsdj500gsljgslpgsndlprsetup.shpdf2dscpdf2pspf2afmpfbtopfapphsprintafmps2asciips2epsips2pdfps2pdf12ps2pdf13ps2pdf14ps2pdfwrps2psps2ps2unix-lpr.shghostscript9.52libgs.so.9libgs.so.9.52libijs-0.35.soghostscript9.52API.htmC-style.htmCOPYINGCommprod.htmDLL.htmDeprecated.htmDevelop.htmDevices.htmDrivers.htmFonts.htmGS9_Color_Management.pdfHistory9.htmInstall.htmLICENSELanguage.htmLib.htmMake.htmNews.htmPs-style.htmPs2epsi.htmPsfiles.htmReadme.htmRelease.htmSavedPages.htmSource.htmUnix-lpr.htmUse.htmVectorDevices.htmWhatIsGS.htmcatalog.devicesgdevds32.cgs-style.cssimagesArtifex_logo.pngfavicon.pngghostscript_logo.pnghamburger-light.pngx-light.pngindex.htmlindex.jspscet_status.txtsample_downscale_device.htmstyle.csssubclass.htmthirdparty.htmghostscriptghostscript9.52ResourceCIDFSubstDroidSansFallback.ttfCIDFontArtifexBulletCMap78-EUC-H78-EUC-V78-H78-RKSJ-H78-RKSJ-V78-V78ms-RKSJ-H78ms-RKSJ-V83pv-RKSJ-H90ms-RKSJ-H90ms-RKSJ-V90msp-RKSJ-H90msp-RKSJ-V90pv-RKSJ-H90pv-RKSJ-VAdd-HAdd-RKSJ-HAdd-RKSJ-VAdd-VAdobe-CNS1-0Adobe-CNS1-1Adobe-CNS1-2Adobe-CNS1-3Adobe-CNS1-4Adobe-CNS1-5Adobe-CNS1-6Adobe-CNS1-7Adobe-GB1-0Adobe-GB1-1Adobe-GB1-2Adobe-GB1-3Adobe-GB1-4Adobe-GB1-5Adobe-Japan1-0Adobe-Japan1-1Adobe-Japan1-2Adobe-Japan1-3Adobe-Japan1-4Adobe-Japan1-5Adobe-Japan1-6Adobe-Japan2-0Adobe-Korea1-0Adobe-Korea1-1Adobe-Korea1-2B5-HB5-VB5pc-HB5pc-VCNS-EUC-HCNS-EUC-VCNS1-HCNS1-VCNS2-HCNS2-VETHK-B5-HETHK-B5-VETen-B5-HETen-B5-VETenms-B5-HETenms-B5-VEUC-HEUC-VExt-HExt-RKSJ-HExt-RKSJ-VExt-VGB-EUC-HGB-EUC-VGB-HGB-VGBK-EUC-HGBK-EUC-VGBK2K-HGBK2K-VGBKp-EUC-HGBKp-EUC-VGBT-EUC-HGBT-EUC-VGBT-HGBT-VGBTpc-EUC-HGBTpc-EUC-VGBpc-EUC-HGBpc-EUC-VHHKdla-B5-HHKdla-B5-VHKdlb-B5-HHKdlb-B5-VHKgccs-B5-HHKgccs-B5-VHKm314-B5-HHKm314-B5-VHKm471-B5-HHKm471-B5-VHKscs-B5-HHKscs-B5-VHankakuHiraganaHojo-EUC-HHojo-EUC-VHojo-HHojo-VIdentity-HIdentity-UTF16-HIdentity-VKSC-EUC-HKSC-EUC-VKSC-HKSC-Johab-HKSC-Johab-VKSC-VKSCms-UHC-HKSCms-UHC-HW-HKSCms-UHC-HW-VKSCms-UHC-VKSCpc-EUC-HKSCpc-EUC-VKatakanaNWP-HNWP-VRKSJ-HRKSJ-VRomanUniCNS-UCS2-HUniCNS-UCS2-VUniCNS-UTF16-HUniCNS-UTF16-VUniCNS-UTF32-HUniCNS-UTF32-VUniCNS-UTF8-HUniCNS-UTF8-VUniGB-UCS2-HUniGB-UCS2-VUniGB-UTF16-HUniGB-UTF16-VUniGB-UTF32-HUniGB-UTF32-VUniGB-UTF8-HUniGB-UTF8-VUniHojo-UCS2-HUniHojo-UCS2-VUniHojo-UTF16-HUniHojo-UTF16-VUniHojo-UTF32-HUniHojo-UTF32-VUniHojo-UTF8-HUniHojo-UTF8-VUniJIS-UCS2-HUniJIS-UCS2-HW-HUniJIS-UCS2-HW-VUniJIS-UCS2-VUniJIS-UTF16-HUniJIS-UTF16-VUniJIS-UTF32-HUniJIS-UTF32-VUniJIS-UTF8-HUniJIS-UTF8-VUniJIS2004-UTF16-HUniJIS2004-UTF16-VUniJIS2004-UTF32-HUniJIS2004-UTF32-VUniJIS2004-UTF8-HUniJIS2004-UTF8-VUniJISPro-UCS2-HW-VUniJISPro-UCS2-VUniJISPro-UTF8-VUniJISX0213-UTF32-HUniJISX0213-UTF32-VUniJISX02132004-UTF32-HUniJISX02132004-UTF32-VUniKS-UCS2-HUniKS-UCS2-VUniKS-UTF16-HUniKS-UTF16-VUniKS-UTF32-HUniKS-UTF32-VUniKS-UTF8-HUniKS-UTF8-VVWP-SymbolColorSpaceDefaultCMYKDefaultGrayDefaultRGBTrivialCMYKsGraysRGBDecodingFCO_DingbatsFCO_SymbolFCO_UnicodeFCO_WingdingsLatin1StandardEncodingUnicodeEncodingCEEncodingExpertEncodingExpertSubsetEncodingNotDefEncodingWingdingsFontC059-BdItaC059-BoldC059-ItalicC059-RomanD050000LNimbusMonoPS-BoldNimbusMonoPS-BoldItalicNimbusMonoPS-ItalicNimbusMonoPS-RegularNimbusRoman-BoldNimbusRoman-BoldItalicNimbusRoman-ItalicNimbusRoman-RegularNimbusSans-BoldNimbusSans-BoldItalicNimbusSans-ItalicNimbusSans-RegularNimbusSansNarrow-BoldNimbusSansNarrow-BoldObliqueNimbusSansNarrow-ObliqueNimbusSansNarrow-RegularP052-BoldP052-BoldItalicP052-ItalicP052-RomanStandardSymbolsPSURWBookman-DemiURWBookman-DemiItalicURWBookman-LightURWBookman-LightItalicURWGothic-BookURWGothic-BookObliqueURWGothic-DemiURWGothic-DemiObliqueZ003-MediumItalicIdiomSetPscript5IdiomInitFAPIcidfmapFAPIconfigFAPIfontmapFCOfontmap-PCLPS2FontmapFontmap.GScidfmapgs_agl.psgs_btokn.psgs_cet.psgs_cff.psgs_cidcm.psgs_ciddc.psgs_cidfm.psgs_cidfn.psgs_cidtt.psgs_cmap.psgs_cspace.psgs_dbt_e.psgs_diskn.psgs_dps1.psgs_dps2.psgs_dscp.psgs_epsf.psgs_fapi.psgs_fntem.psgs_fonts.psgs_frsd.psgs_icc.psgs_il1_e.psgs_img.psgs_init.psgs_lev2.psgs_ll3.psgs_mex_e.psgs_mgl_e.psgs_mro_e.psgs_pdf_e.psgs_pdfwr.psgs_res.psgs_resmp.psgs_setpd.psgs_statd.psgs_std_e.psgs_sym_e.psgs_trap.psgs_ttf.psgs_typ32.psgs_typ42.psgs_type1.psgs_wan_e.pspdf_base.pspdf_draw.pspdf_font.pspdf_main.pspdf_ops.pspdf_rbld.pspdf_sec.psxlatmapSubstCIDCNS1-WModeGB1-WModeJapan1-WModeKorea1-WModeexamplesalphabet.psannots.pdfcjkall_ac1.psall_ag1.psall_aj1.psall_aj2.psall_ak1.psarticle9.psgscjk_ac.psgscjk_ag.psgscjk_aj.psgscjk_ak.psiso2022.psiso2022v.pscolorcir.psdoretree.psescher.psgolfer.epsgrayalph.psridt91.epssnowflak.pstext_graph_image_cmyk_rgb.pdftext_graphic_image.pdftiger.epstransparency_example.psvasarely.pswaterfal.psiccprofilesa98.iccdefault_cmyk.iccdefault_gray.iccdefault_rgb.iccesrgb.iccgray_to_k.icclab.iccps_cmyk.iccps_gray.iccps_rgb.iccrommrgb.iccscrgb.iccsgray.iccsrgb.icclibPDFA_def.psPDFX_def.psPM760p.uppPM760pl.uppPM820p.uppPM820pl.uppStc670p.uppStc670pl.uppStc680p.uppStc680pl.uppStc740p.uppStc740pl.uppStc760p.uppStc760pl.uppStc777p.uppStc777pl.uppStp720p.uppStp720pl.uppStp870p.uppStp870pl.uppacctest.psalign.psbj8.rpdbj8gc12f.uppbj8hg12f.uppbj8oh06n.uppbj8pa06n.uppbj8pp12f.uppbj8ts06n.uppbjc6000a1.uppbjc6000b1.uppbjc610a0.uppbjc610a1.uppbjc610a2.uppbjc610a3.uppbjc610a4.uppbjc610a5.uppbjc610a6.uppbjc610a7.uppbjc610a8.uppbjc610b1.uppbjc610b2.uppbjc610b3.uppbjc610b4.uppbjc610b6.uppbjc610b7.uppbjc610b8.uppcaption.pscbjc600.ppdcbjc800.ppdcdj550.uppcdj690.uppcdj690ec.uppcid2code.psdmp_init.psdmp_site.psdnj750c.uppdnj750m.uppdocie.psescp_24.srcfont2pcl.psghostpdf.ppdgs_ce_e.psgs_il2_e.psgs_kanji.psgs_ksb_e.psgs_l.xbmgs_l.xpmgs_l_m.xbmgs_lgo_e.psgs_lgx_e.psgs_m.xbmgs_m.xpmgs_m_m.xbmgs_s.xbmgs_s.xpmgs_s_m.xbmgs_t.xbmgs_t.xpmgs_t_m.xbmgs_wl1_e.psgs_wl2_e.psgs_wl5_e.psgslp.psgsnup.psht_ccsto.psimage-qa.psjispaper.pslandscap.pslines.psmkcidfm.psnecp2x.uppnecp2x6.upppdf2dsc.pspdf_info.pspf2afm.pspfbtopfa.psppath.pspphs.psprfont.psprintafm.psps2ai.psps2epsi.psras1.uppras24.uppras3.uppras32.uppras4.uppras8m.upprollconv.pss400a1.upps400b1.uppsharp.uppsipixa6.uppst640ih.uppst640ihg.uppst640p.uppst640pg.uppst640pl.uppst640plg.uppstc.uppstc1520h.uppstc2.uppstc200_h.uppstc2_h.uppstc2s_h.uppstc300.uppstc300bl.uppstc300bm.uppstc500p.uppstc500ph.uppstc600ih.uppstc600p.uppstc600pl.uppstc640p.uppstc740ih.uppstc800ih.uppstc800p.uppstc800pl.uppstc_h.uppstc_l.uppstcany.uppstcany_h.uppstcinfo.psstcolor.psstocht.pstraceimg.pstraceop.psuninfo.psviewcmyk.psviewgif.psviewjpeg.psviewmiff.psviewpbm.psviewpcx.psviewps2a.pswinmaps.pszeroline.psdvipdf.1.gzeps2eps.1.gzgsnd.1.gzpdf2dsc.1.gzpdf2ps.1.gzprintafm.1.gzps2ascii.1.gzps2pdf.1.gzps2pdf12.1.gzps2pdf13.1.gzps2pdf14.1.gzps2ps.1.gzdvipdf.1.gzeps2eps.1.gzgs.1.gzgsbj.1.gzgsdj.1.gzgsdj500.1.gzgslj.1.gzgslp.1.gzgsnd.1.gzpdf2dsc.1.gzpdf2ps.1.gzpf2afm.1.gzpfbtopfa.1.gzprintafm.1.gzps2ascii.1.gzps2epsi.1.gzps2pdf.1.gzps2pdf12.1.gzps2pdf13.1.gzps2pdf14.1.gzps2pdfwr.1.gzps2ps.1.gz/etc/alternatives//usr/bin//usr/lib64//usr/lib64/ghostscript//usr/share/doc//usr/share/doc/ghostscript//usr/share/doc/ghostscript/9.52//usr/share/doc/ghostscript/9.52/images//usr/share/doc/packages//usr/share//usr/share/ghostscript//usr/share/ghostscript/9.52//usr/share/ghostscript/9.52/Resource//usr/share/ghostscript/9.52/Resource/CIDFSubst//usr/share/ghostscript/9.52/Resource/CIDFont//usr/share/ghostscript/9.52/Resource/CMap//usr/share/ghostscript/9.52/Resource/ColorSpace//usr/share/ghostscript/9.52/Resource/Decoding//usr/share/ghostscript/9.52/Resource/Encoding//usr/share/ghostscript/9.52/Resource/Font//usr/share/ghostscript/9.52/Resource/IdiomSet//usr/share/ghostscript/9.52/Resource/Init//usr/share/ghostscript/9.52/Resource/SubstCID//usr/share/ghostscript/9.52/examples//usr/share/ghostscript/9.52/examples/cjk//usr/share/ghostscript/9.52/iccprofiles//usr/share/ghostscript/9.52/lib//usr/share/man/de/man1//usr/share/man/man1/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:22354/SUSE_SLE-15_Update/0db80e087dcd89cfa13924316467da24-ghostscript.SUSE_SLE-15_Updatedrpmxz5ppc64le-suse-linux      !"#$%&'()*+,-./01234567777788797:7;7<7;777777777====77777777777777>>?>>>>>??????????????POSIX shell script, ASCII text executableELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, BuildID[sha1]=ef12ef084a0dc58e9f2e7898b6ddcae98cda973c, for GNU/Linux 3.10.0, strippedPOSIX shell script, ASCII text executable, with overstrikingdirectoryELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=b124ee62b81edf8d52527557674d4e2a7534f957, strippedELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=0238f34b8e2ec051a91e3f50e8b4d468458fcad6, strippedHTML document, UTF-8 Unicode textASCII textC source, UTF-8 Unicode textHTML document, UTF-8 Unicode text, with very long linesC source, ASCII textPNG image data, 194 x 40, 8-bit colormap, non-interlacedPNG image data, 32 x 32, 8-bit/color RGBA, non-interlacedPNG image data, 108 x 119, 8-bit/color RGBA, non-interlacedPNG image data, 20 x 15, 8-bit gray+alpha, non-interlacedHTML document, ASCII textTrueType Font data, 16 tables, 1st "FFTM", name offset 0x3be414PostScript document text conforming DSC level 3.0, Level 3PostScript document text conforming DSC level 3.0PostScript Type 1 font text (C059-BdIta 1.00)PostScript Type 1 font text (C059-Bold 1.00)PostScript Type 1 font text (C059-Italic 1.00)PostScript Type 1 font text (C059-Roman 1.00)PostScript Type 1 font text (D050000L 2.00)PostScript Type 1 font text (NimbusMonoPS-Bold 1.00)PostScript Type 1 font text (NimbusMonoPS-BoldItalic 1.00)PostScript Type 1 font text (NimbusMonoPS-Italic 1.00)PostScript Type 1 font text (NimbusMonoPS-Regular 1.00)PostScript Type 1 font text (NimbusRoman-Bold 1.00)PostScript Type 1 font text (NimbusRoman-BoldItalic 1.00)PostScript Type 1 font text (NimbusRoman-Italic 1.00)PostScript Type 1 font text (NimbusRoman-Regular 1.00)PostScript Type 1 font text (NimbusSans-Bold 1.00)PostScript Type 1 font text (NimbusSans-BoldItalic 1.00)PostScript Type 1 font text (NimbusSans-Italic 1.00)PostScript Type 1 font text (NimbusSans-Regular 1.00)PostScript Type 1 font text (NimbusSansNarrow-Bold 1.00)PostScript Type 1 font text (NimbusSansNarrow-BoldOblique 1.00)PostScript Type 1 font text (NimbusSansNarrow-Oblique 1.00)PostScript Type 1 font text (NimbusSansNarrow-Regular 1.00)PostScript Type 1 font text (P052-Bold 1.00)PostScript Type 1 font text (P052-BoldItalic 1.00)PostScript Type 1 font text (P052-Italic 1.00)PostScript Type 1 font text (P052-Roman 1.00)PostScript Type 1 font text (StandardSymbolsPS 2.00)PostScript Type 1 font text (URWBookman-Demi 1.00)PostScript Type 1 font text (URWBookman-DemiItalic 1.00)PostScript Type 1 font text (URWBookman-Light 1.00)PostScript Type 1 font text (URWBookman-LightItalic 1.00)PostScript Type 1 font text (URWGothic-Book 1.00)PostScript Type 1 font text (URWGothic-BookOblique 1.00)PostScript Type 1 font text (URWGothic-Demi 1.00)PostScript Type 1 font text (URWGothic-DemiOblique 1.00)PostScript Type 1 font text (Z003-MediumItalic 1.00)PostScript document textassembler source, ASCII textPostScript document text conforming DSC level 2.0PostScript document text conforming DSC level 1.0PostScript document text conforming DSC level 2.0, type EPSPostScript document text conforming DSC level 3.0, type EPSX pixmap image, ASCII texttroff or preprocessor input, UTF-8 Unicode text (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix) .RRRR RRRRRRRRRRRRRRRRRRRRRRRRPRRR RRRRRRRRRR R R RRPRR||!÷M#cups-filters-ghostscriptghostscript-x119.52-161.1utf-811bc242ec050c82676a1b2dfa10bdf8d81d3af328e2f77e8b32face6a8f126c9?@7zXZ !t/]"k%f%w\ӧ@]b͕dz4אfVYHQ\-h_@NaJ[cBƿB>O~?m= # [:%nW[ۦ-Taf}GP+XY/r xyK~]9?>OKˤY [sUN?,np'#&k@ tXU lE(6_9 PځcL=m鴨"j0 IzgcrZ-Y9Tct LlfMҗ Vy{e튯SBq|*Pюhmvc^xL]KYT}PĶD*̇yпR6lAhn !{Us$OMmAV֥I$I?UXbGRtA~%J!LuOHZ7.g:*\QA\i1%IX&S\\ףw(:a,"1SZ=͐Gf0LnL:hJUnΓͪS:rfQY4J~@= i0 8b/@,V5.ʹ<'- vYH8.̈Ȇ~T12FVU զHLgict'&:̹qy0p8yǃ%(ITX)pIOWĕv<<0 "́6o/ \TsDxiL un4(Q].4eŏ|- T8=f x7ʔBPs.@d*j҈߲V^O551(2Ց !9\@+l|ʃUbbsV^^ [k$%[ߵ]Ytf3>gc02ect{ڧ``TSXV-0wWF ?0s2ҎҎ?tT; k+^dl}ZGFc9cJM a*b3Il4;%IݢQ1@ƄCPo?^O ^PDD!3 z‹UӻbbT`!q>VhhT!O̟#J2,nod&"AR%Ĭw5j]_?Tgȅ;WO&|&?7iȌ&Zmmdq?.\8lS`HR\I m\o}2}^NK5!61D[aq*3eM8rfL$x J1vBjO0ZN\w& +XsZ7# -Ljִ~e=pZY=.>L)!9G `W*R)ba nԹnDE%yM;T$L5x.^}BMQ9r5Ix>΅6cZl֐k3n,8)uXyX5./w͔LHSC;6YAMP87+Qt4asaaf%6?s+vT);RGvi^!6vsw({E41o{S50Pw9l_V{J R"UH.5Zo0qH8)`&.O$oc_~!N=zy̆+My [#e~T:V[ȇcaۡW%\tD a* :I,VOnQ%wC1 o|hK"m@V>MB8+P 46˺ÑIÐ$EX܇ Рΰ\z(8ዛa%I髦fpWO_uc8Y}֐K)Mv<[ 9{\E7|Lqi={p Dcmk~+ ^(8 M1GWpo1k98Jt\ eץ Yr,:Ur 9+_&BN +Ouxm`%]-17o]Wx`&YH>8ӣRZ"C^ro4M[WUՓ_/ ʁNuUߏg)i(_Z= N}U9&Edu,1eN\$ڏAU^ߙʨFeu 9 5=ڧ7{8P#)w?`Ca Rvkzإ$ y ľVm R 7:Ja U^Ҵ=j/ 7Ӆe.Ds힓Xt0WAB)m(&4ЯsԖӼ:3FX}`tGD~xZG9E`h Z/qohAp_i<ߚ$ o։zܧYT4+tG˟b}=hhnuOWueT:_ +7Hx)9 ZM+*ѤMcۗǨ uNS؛}"eCmLtzErD'kG}8F0Y`z'l17U(㫉1գ8tD;Um%ggQL `|2oк!)VkAw?rM<DnYj ct9HwXzL~;=kmǰъĶL# &.d0x}~%.g◖z~ ?Uq@'꓂ӂ@V-)J+NTƼpൎոtg=c*ʎ4QN-рM#z&Zf],Ƨ$`#ϕԩW_?w1J1ΰ| n^a"r(vAwH)ܳOpQSFL p/{Iwy::9҅kY:ꌏƥ]lٍA9M_'@'_?mݢ C0lx[(qg#'^& IOWCSw95!zufYe̳3KYٰ@FF:yFRӑaCC/gv#N!uHA$k>weMl"eb8|jΫ*`a\~L:hٰ^[6`CP\߄fr=dd&C8@v0GPfJGP{2Y1rlyZʄfϳD4:k&ʭ,!ht[Ս5o\eQN 0JgaTT6¨)]<Ʊg(>#iS*!a]|uFl\d/idtG:C B<_7oy\!N^' ;kϗƼIZ\^u|uczR2څ: :'r7yI(s_f' q ֽ@eM*0r^%(∉JƬ 21 B#0;*<:p(?g J0ul6'C"[XpIYx,[ENb͙@^/)ubvy $uV T 1"F#FwҠGZ#q_͝J hn[-eM;!fUCg\2-|Z_l^Ĝ,4֑-tv=" N @cS,t>Dlġ Z31\}ب?y=WpoҨmTOz)∮ڦ b|..T8N.L-rY0q7 o d <dzн};لhZ]AYv!P1X,TQU7?^iM$MprIFv=Gn3KْM_ڿde6V> n}ZZ{ߍ}珃ݜ}/Zt 䒓L㋒iMW5]ng^\[)!z9}b^;9;=QC]I3OU?ל}48uz +HeH:ɱRW)CyG`c'{\z 02 U+}&m::{;[,CE [3 {tBZ1Lb47%^)4+^p`[38糶"%;je[].7gvW F,ǧ\r\iƒAH]hL>1[Y_alj`Һߊ&.םU[A&l궿ޟ<+cjÉk2]1E64 }4hpxrc9 ΀x/NKU#dըv.^QI6a''ʒz f6}ҖZ5<ۘ LqmB@D|1վnh/b+?6cle[] Zw=~@N/+4N!rnO_SXD7 Z8ZaFElZK0)G 2ã{;'Xj%6ļCi'8!( ms "Ϝ3|L  ޘQ52kǽ ƸF;ʎ$9p]gpI~/ H2yXbe̲k7[ǵ vZ,fKFE=ǎER};qw;<\_͆g#@z/&?]szV̾*zkչZ_$apVEw'JTBi0q17ZBjT#̩u?TR+ULqjf"jtsi>Xn(w?EYΑ`*;@/ouLsZC[kIx_H10TˆiA?rAz ߾q;!k{мIIvc֙!4'{irlBց ` br;:* R"q"?ɧ`j>qXޯBޅƪhQ/}&S+CIѫ!Жhtv/@Zk ~jnǰT KB PD]mz&7>qqҽ~$ ܯyt5\ñbrP(*EvGNE_"nKH)k4gRS]7w"><\X "R7>3m,N)G+9Vlڙ| 4&L^q7w{((qi/h.gȀ,'*qQ:T~yttL)LJ.5>G|*6,6Jޤrh1DbBh3;-ec=CCbdfNy*6Mb 8N ժ)u{?n 6\ݴ 2kN LAZWSvv2~u&V2 \I,JlĹZUޭ^.pO/ :Zk5S8j p:ثru2w}s1l6 (HԌPSǮOJbc͗.wEc;pl^J/3]]] (#?ylJa~1Ow/RW?r_$orԹlùXe}ŇKn? 2c[Ggs91:՗ܘlwnPo{oHdnS뵳b d!\K)`DЀdo ;M {IZ~~_/8Kj'2Xw9"yYȫUHBrLj6Մ>ZNtfG0gm ^ÊΓgurIJdvO<!Koj%~q;쵮LRbD߳.Z7W6*ۊuϸ8I2%߮OopE^NhEy_܂T 7%rUqZ[_9@ާ{*`ȿgvڭѰK]>kED50;ߺɯ4o48e)[KzpBT.O8bҦ4LГ_ >'?,urms4PYB:ՑO'8I#N_ؚ)k>F}lg!W {e:s)IBD]) ιiـ30=td'FiLq/:+ ]Ii.Q#krVsh4 ZL[*/ LmiӼّpC7zvy U{F8"c(/ȨRh9=CPpu`D.c4c`lv$KѸH>-ytjvfy@7ɭ@f_[>+ЊGE˂Jm1+?:,cw(}WWVl?[60Ql]%wnݣ}ـܩ{B7U TA7D=RVa4>|pdrme<ڄG>:Q\ 1 c^בK5u xfUR1Py)7؁gQjTOS H4v>"P$䟞 zDR c=^ҡ "R[#lk`!k_z='D Hi8dP\9gDZitK$iU)Z5jެ.I$慛LZE-8 0D9d)D4iSkU-ya?34T{uxHV ~YFa<^T6S=j/H[ =Q}HY("ꚴUaZTXNwQ:LC%jICXA_螸l)doėla߉^:syrz*#Pn`ȔEQL vb3$](eB4*.Y7-`1h{k|qHBd"wΓ??Ǽ`x?[ tt|ȓ~diN 2CafQRN!IaH2V2)8P߹bGY6B_eLy"z m[*a'gtٜWg?oAlzP"|oi[ 6umV-kFC¡1[DƷu4.N-`k.X">uE>_ÍXswĶDέqya1v!g j:B=݈5a%P"C$"BRTrvK:Ls<Η>!YS6JCD(4ok$Hi0(U^HQdU}{;Lw&Ep eSR锝Ifq(s,LOW*=  ʃZC6*AۇQ蕴‹]AjTt8aSl8X$%( oÅ +,a ϨI@ÛcJVtQ; s-D]&e{CQr95D4 Ы~6Sye3sj!Fq7d;K * 񬫀(M{]GS:ঃ̳y1i >~[9g)E}sD=1铯' K@ qYwDJ,Ybp:f%amDtD(A//b@_ڵ/kE4CO%QkgI"t#D}?{xc.@3 UBe f̌3~FV^R$kխBΙzݕ2kޟfèҤ<&4uNؔ Ҥ Ov`!Q7GGV~ۜ lhh VvOĆHDxdmVuØ8NjA,cRnBՁ. (e-}TMuaq- -dDқVR? J #ez&[Z.a ܶ UeqŘg?zQ&tdUfh\108FಚHG&Ť۳i22yG-J_:T{j_RE;b<*F N*%̡5EwBTBjv;%3#d71^'CWVzAE uUX`MͯG i݆0,x&:n1ʁJMT0vQ2$_ ~:_:wh=8ٿc 5 )/QkQObdVNO ڰ9.8@!{A@L=DAXpиuƶi͆h2tK, +FbV?h̫CF1׊0YoW5\u#KFwc1{4<+9wlpz%}4':ZAi͠CHhW}ˋA;*>?ga!x/suѸmiTfHLy-vsOՇezkɢh-Ƿ swU7i> rR<]*g?VԱ>&=՘*rg6'ހb8 wsu?=(F־?6i&~+Þ|ʜ&l۔,Z%V2ŋnMwMXÎ>iD0;:hI<9bJ.V@o A[sl9:GI-_Oi+洱/my=ޣEkJ+5& G,+݈܁y2Ƕ"`^OG̺*aY#6d3|3t%=୺l*+mN=fkO1 *6w_3N솽؏AF Ȝ==WO8G &6aӌ^'v3)Cc<@dۆ!a z<}Jj.%s8ymQ*Ձ&#މ-\wה-=zHG\Z+/Vu1Q.EKD^#%.6 pn*}Y L'7-ZhwAȢؘݭ Z( ScPtkOq:ZAZZ_Wh~-2H H wz|yφHJxHh7Zp+SvUH@GKB\'d+;v$˕^h>zT!Yӡ%E-XWQDtֹe:B@v]’LpWO[>tN,0C4>Nvpϐ5Tj\ 'n(:c3A(R-7ჍSafrE(&WkD'ѳ; <|*ܒFK_Cs+ybv2r2Uj aE:H +xG݇ױLQL@)=Kj f@4V–h:Cj^T\ ӟ;\ؼ5I2z?R;S>BLpSaNU +FUo1g.M"I]A͔E6l>&]M#r'_Jh"ysj"ڼ͋N)!8i>R=$aHДm*n i8 #![W16g'pS ԫ}|@dTLg'CLK>,X9a15ĥ6Էϟ0$Sn.뵊Y{~:ZaeLP}jo.}DLm\sW| 009~lqul`cd'R_# M_gMx2rIo r[M(`2I"4o%hKi;Q{4OV,,t+)BX< fρ%G`{DBNSvp wBa(JkSR[6Lw^( ;|qa//5?Y"v Sw 7O"&%6Rh!mE1U;27[1mL<"({؇(08|$}cTzz|=Ũ]l]Suư #X<ahj6^pg)"qmx /lZHF.-9,{pmI)S',S]!39QvR)_,ssVy{'7t2ima&K GhSPԐ)96|in&j٭^ύk}T;[H&xo0hև cIֹg R5MaU {Op>tm)WGLV߳hW\ӯF)FKX9fc dc5f"Yd&4+I_oaΏ6qY{{r ΫC{Ž:(<#x0624 ka eBAL}C=x;]3iJlQ?j;Uƾ1q8.Y-:7Djps--0)GF6z_n#4\9ReV.vQmr>w훤X=0q `IIFv`,2w:Z?h/QzTi+S|PmWUCKbf_`gEռ;k/=̇<=?Êثpu$ū1ج#,l<^jj<6;<ʲ1[} ^^n|DDŽ]Fe&sH$ ~ϵgJyWX8Wg?E8Ǎ ˭kϴ<L >{-ȿ#Xi3Ol~!ӇA~#9??"' L @V`q΅靐_tg.2lxUWiqm3VNU`:}cTʫxmsm+G.7әyWS8i6=Q=LoM,[9_&ưڼ QH@/M`e[aWJ4*ST] $7!12t6HGiZ_șp;_|G  `XƃBhI;;{;`VU6:>mtHDé u!"`)<IeX+؋1H-9Eڣꏸ-wkˉY"2-[p\. >[dTMxWֹ_"=>=D_~=Uw}S:*{4p>Vާhp)͑,n2]@*?{;+\6h D'HF?!-Hd"4Zޘ6`JA׼ G9l!] ďyXiĆr੗,̰kqjUb,<(dդkfoFL[1&Swk$ctJ#HJV J2~,* &TzSH\4!\@e2F:AE ޱI(1v^?Ah@^q㣖bs`K z H,pezgsl1kk1ʯğKyτ <?&aȁ/R@o ~U-Jl̢(C{7f=21,?{C:zI趡S@qB6eH:z)1ldwj\ޠ# ̓#ܛ ߖٙ۟g ՛Mޝ2 Krq)MVy oI)6w r6*b+i뮥0OLB/0){?)VmY˱p GSNһψJdjcz+M>ugm4?{ӆӪ`' z-匭64[؜CGu:jә_y "عPoz1Jgh6Pԇ1Coh,h96m4wRzDo(4܇z T3]AC;3g"f<)T׍hDJŭпj sj܊J#Gįkڅi/o<h(XpAi-e,މ$!,jo!dȯˠ PiOƭ\& up^="[鞔leFf-.:(wl2F?|7PLl✦p_%kwJtc<=S;fH^Gt!ؾ[-/kˊ7sIG be+PFϏڝϠPB_-1u9#ЩVMjIpz>ch#!LÕڡũБ:"ӴuK7s׈yu3֌aR\ OckCFԏيZ#g˽5SOLzXz)JfuQ^ӓcHޏqZ.0`ࣴ$z-pRu')IsYh&!8q`a!F՗8׸JѻRx9S}Iдz N%ќ>sŁ+{ 'ڸh~X#S .EJ~ a^6(LO:~s!5Exa@g=t>A[N46MI&hVC7gȟ!6OHkCՂATc?®JIF4dR@xSg+֤z c6dwCm5$BY >.',#ą cd>{{6w{dW:$fyaM5VS!6OVTˍs<2>REÚ@^|զ^`R]FQٷ\d<}vtCMcޙUۂTLBQ:;Nh!=5T Ij e- ?j\,BgQnAK›c lכ+׭!OɬE"fRb1KNz=O=r憰8xPfJ؉8ȒEQP4r8%2܈0bq\vp4c>4^!!Zl{d׫.Вm)& =ˇ] ѝYo_Nf~P G% dyvDZ3qZCm RZ\åS4<##7%a&GrIK"N12 ~" c^vbW= ؅Is6˟˅m߅jECXF GhUMNkl/dZ'\K-JUӜ&N.jʉ'MK2A&#"{$gOTBťt!F="Eԋt$sُG0y_ nRЉ1<&lN46!KX8b;f#$% X4Aa#ttuEvWoMY P~J=)3O4s§!gXr h@ǂZM}XJ$R&_A Rf6P6֕F c<`f$A F8~S!aaR~͵^r]eH>>1離{@;ũW6oI֓`~;\$W*lD `$L"*ڂZiZ)lY*K.u-vTM9K8Vp9S>,鎩q(< ԠS0TT1 T/TV+g:7ezz UsxHo} >'  t7-4[v σg-wir?Eu'%DHG1Ks,e,qOZsu=bd<%౹ VᎫ줪z:/X>ϫVӆ2nh;(W5xJӐv,-q<~I H[S#TvKEI +@ *G*AVP颁JMYyzh`L`\v7;B~!\փA Nӵb'q˱)C^Wjxz606c hk`$I&]mW9mh}| _(ȒBx*LsVIwp"ɹj~ฎO U,гvʩFnq W y"o* B^HYV&C 2b,U'Xt(׹]<=⥕ܼ)12=#*3}Uy2N |OH$M^3֝Cst."ڣ_b ۈ:1fE\B;"knK*f͎̈́%*7'l.^ 菒ȧ8B!7GI"CD !\i@nԞ p(ʞҭU؈@eLEKySx R00,%uK5][}Q}?n#*8HH:nxSBkϴgfFᓊh·{X)V}*W6P'ChTI\ ΙTZe7ek>=.dxN4%0 OCi 8(${mraqE*{{aD|>*$H8?Z8-H kuWz`}[ː2/x<jj{*sXs*}U&٦v4b'^wDICm^$DmRf4BpcK$g[9"kOZKvv2.3`>V_<3i8I`ۿI]ƛ3nc<{H-RI'u=chy&&@cź,ezi:i1~+ j~%)9SLľ[=!54Lډ۹@Ի$qE5ՠwH\]'͒ׄ2$Pe\TGk߹-忝,Ȓ!#?lz9aTp6gଉ|۱2>}X*t756ߩ~_tt1pG;x/1&M}H/,lpւzV1n zM9~;*Z->d9>eI~3|/ǜ|6cJ8;T((M284x!W Vbi GqB[M1w8y s68u"&,R̬NyI&@&R}ꅛ![ںLӁm39_(U٬bWKI^}1s3 pM$ܥ|Hk+TaH{PneBaτB֖(ƿ1HPs)9[lL^4 PvkYOKA lWO eIݵߧtn;F[@iA@idkDwoiδ;å9|moO0(*jWne9 d^|(~)O]PѥѴm+o~dh!Zv918e~ȍDŽ9zD! ,ʞ7 Qj Q9f.ݨ|Ud$bj ֥\,e Plggҵ*V ـxCvЏdpNDrФ ov $ک,fEfp]*\a]XX ][vą bL5AXok,H-*^OUes[ڋZt@tޞ>S/9]C6.}iL;dhMC3b?ϛ.^+L)=" J-o"\c*̄`!|b/Y_s8P p4d+%QPHb ruQM_tZ#٨II^Gu_3:_!+9_@V*,}5a't{PzpjXue+`goH*n7UjQp4--yVb~#U$! :@D}SvjR~fm ZlR۶ZG`遺2RֺxGĴPSI3++ڻbKB٘Ջ>pZoG^bUCfÀL a-cUr=}xے@Phٟ]d3ڬ@3$GmS>0 ZGL.dqSP(#WUWסQC~y(cz(VC᝚1}A:tdcL`zM-"l6'@T ~>1O.+zx ›I\&Yssœ:`bc(ƁչiGJ5>txf'0lu1֣R"D(,ϘB"ْ^G#GWh iBϤ`%Erf&%5qXAI,$ji Bk FT~ w;FNuk Sp4 yJߌPDy&up=LOu"6QTwXJʳS Pvu99-hxp.)G7_\nεshx,/*Ciyѥ! ax`?96?`M%1,dtuw[Lн]/7NJ\ܖFPUvdR}rIP}W0uMJQ/%wvyߪ:4/Y x!W!59R*j\FKrUkP6󴃓/E}MʤtK|W*EC乕΍]lHI, HA?i[ZE"lՑ~tMu+p~<%ĝWF / & z4[:H `v3z~E? ݵOם-W{lDxͱ~#ݟÙ.۝7_hjƵI)s~Į(.fx@" k z2aL{iF暢Q`rA^ޒB{OF {ē E[ ?uu0PalL 㷋&7WMXR?o=Lc!s^\V^&<8`cS`"%~"11eD"k.Dr.TAܣꂖUT#I~T@h}ҨбK:\-_XfaqSFiQ?P;nؠ i@E6_ǯFI%:UPa 1 ۋѩEx}zo@x-;;oTh9%w4aS-ӥ@r\ބFg%)7Re׺\ IҤl&F[dN`2Z*N"d1 lPl-O+<:[0 f,nĬxFbJ`U[.-NV9wCj?~'ѵ uR𰮋ItJLpoR2VGϘr@ݻz*}o$y ?rƞ]B'v,(|wZ7Rx|J7(.\12R=HُQ@U>09>(MSZ8Zu{kuq$:DorчIfق:l*ukrY18(tZMW7;9ޑ'C*B)H hA|xׂٓ.Q,A_HyߍB- ^ƸL-*|I3|ߥX!tQ ݛ fX{&%㌌!bSfuY#Sgk1<1'X1+Y)21~++Bfop%er4J"l" 􊠉(>a'Z6Z+ Y 3=k:!g]EΗXs83QqvMyCvlNͼ%)ZJR.҈S<"<}G YkZ>_٣unP[f'ZraÖ ,>7wkq8Y 7 g>װUךL-j#OXjzm Il&|xC:V4غk%' Q1s8uӡF{o9xҤFոKLRǷe*XJ]tK3H!A03c {k X}"~u)E_pxAm>4;  mqrRFt#z["V2Эҡ]X~;/V %6B+~ "`}b#͆d#43Fzep3:"%LX0} {"Ci5B(epڕ8w@mh\ gY"_riU#˱! }U@Q0(xkik|7-Z`Nrn/c94)$v⻳&SIAxx<8d&撏!RgPHeN]ߒ!Ullߨ5_ZWELvtKNqfDžMԶOȘP68ub5Uy@݇~s jZ= ~8o@,{tjJln1{&dݢ3+K2521yk/) /߅xS:&ju ^%P;/(D;_VH}۶RZ5:1Z]J%߀\1qLU.e mT|SGq0NZ;Z#FeXůeis^V#;2?f"l/~ ZM1Y;*_I xX~DyTPv;`Ilu{3w]3ey>HY R KV-.~ua*PXdh/M?oTN?P]>j%܌)*ʕ[90DlUis-> %Fqzm[+_P!!5u>"/OiczYc9(c66!oAw'm.=͝KYhh1XGiգ +YЮ qp/Wֈ_k6֝n0f 7" n`UJ1 x#1R,X  gApA!Xp4X&T &iHhӝc" aňqȇ1>3rʳd]tVK.'I齺?4_[bejqIm"UAgO\7tPaq;q&E|삾*TWg3ĺi)DvfSBʇWM-1@g1KcBIuDsfK6 \-OõMQ$? _V )ؓmWDRq! RME۷e5%pE*L3?'IIjLݛ,WgđKxxR-J^?]^y  p\u =Dz<Hw/Qh!^95=9QX`b_лx"PIAAsq* dh|N=灡_Vub&ثӯy75=8@ċ'-uójVffA7|X!m }V,hI| ʤY"Y uS^?x`"; Q3'X002Gdjq_!ƈ3{ ?ӔVh;vOT<gmB? yIW(`NEy=.K|P]0EE4|+wZ=uee_+B+SOw-xL}o.|~9`Y^?mL~Sm|^yƩW,;3o @iU-pHvOtAfV駽ԵtL-^K$s~B֮J7yxvB)31O/y/+)0w|iߵ,SA'=`~o7H#{ckG>&>1 Q/ -d:N_BI`07HBg ٯ/ut, :ċ,#TY?{0ZC q,̕Ë#B*SITl8,NF ^(5X5!멣֝cHVT0|+m8z(sP%鷩"#/=)>zC '{9q =\ynbi=3 A䲘 ||7k"Ix}އ FUw*YPðf-s}l.*d&U\Ze@6uHu  c2Ȏ8/fd RZz?j'3 (rdbOcvXg"=@2^j4.hlS`KAhjXʈ?{GEk$j qwޘ[߲|֜~'g?O8稢NUGl3SvNޞIۮEnKJeU%edG. Ӿ4<)/dWQy֑@SY/~,+wr1Sy9 F⑓3엏Lsi=FY!-39\ a-3 pV_q`FYp.!u 1t.3ᢩvHkE\7*LW)\6&=3^ Bgx^%tv KE18ڵ"veKδO?ƙu"9B1^ϒ~@^d|wN>H]5=uW )wXKO_ߘ*+r62Ű 1#̐hH 9:cK2ukK3Q9٨ hFxzh2^%rW21(a::&Ҡ;xENK2Gu(*ᶱI/ZS̨cy4 )R̋Z s+ m~TM7GfLɈ6Zpvddgc #J 8m9&5k4yTy-251Xѩ绘* @K[@zU1 L샼tU;R^̙$8Y+>Xm88:Տjq,Uo7#w1@{*U~&BKiËjFFiِuQ,#ZX}kqwh<ױP~55f!A$H{ 80u|j];ATuHrGK\|B.^txYV5~90{+niUi|]7H0 `ԣ#v/L(<{ $!]Kwtڑˡx"ȮRP [d{ M I0 K`ZQhM=gnB->=dH"n,ށOW[$ͿEO]+2--k]Ŧ<$AE&b_YmH5# B__ԋ[B<ffwBȢe/4x2qAfڵHo\~U@9u3+7"isRaeHTXri[;|N@h#(55y1e=P-MUd3,:0ߗQf Hd)¾KC`{} o{2ʗC pˈ{zBq̉?vZ8#u.s2{}&#aae"s7R< v]( lS1 Ȋ='1Pz~ 4ُ;:AnJp3yeM}_h(>lZTgBsv6EX 3go :ĝ2Gu+c'b@RC4J+/Da c f}yl3x9-T"sb tr+IzZjK'APQX9zb±EdBM]B[ެR̚_vbFͺYӭE0y!}fs)t}uH@$GkD>ݝ%a"H/> Fՠ p^`/́!&R:jⱻ2A&)o l+=c.ӀGp8A_:ׂ#0>pF 1\:f"}͌zФEG8k.bM+הNeXln.<eogbt,chI{x4>E8ٴII@ҲFRw`Au\Tq}0M5#O/7ζ BbhZA%y_:p߳am0?Q:QK[<׈C#݇H#V]LYeR W)-({}L*E)mL_ ˎLMnZY0G%׎R>puho:ӯlw)EpjzND(fFٹm>.q+vBay:p'RQE5U|"؁C3{L-Nw!"*Fh+H ѹ$m ٖ D[F|6 fv4L7讫 wgK7\#5/MrwXڑ}6L'jiuq'hVQ>&ohN{즹GIo.$S17,[Z0KƴJV?yᘾua$$;Phnn{HR ,^֥Zp~ dɿZַv'P}m.@ ks$y}v?DV(j|9Kn V[I&߆~VB*߫|Z#x4x^:1:};<-}56WZn -mz=ص@6Z4~8d'"M~c㸻fĘIY֢hQh\`P@~(R*%.TyQ NjB& vNF#fYCw!= ަ!o3n6ښsy0hܷd•)9$":s̋!/fζ8}x.zZeU9_U3)MDHx1+{|?/aoQɴJHa`g[C0YVjn'ZI!@)u2y@h#cP2rl=\mxj/> 3X cA\%MFUOݱ12{ΘSZ&u$`&.)/SLN౛Q~i0"$[rWqa}WH-&__6J~& ,rKxdƍ&Rݷ:ɼ-xTcK*PH"837,JUB_x2li2: :GH9F2YCB!\=X9o#ڟzn3bLMj?PPq A> plgұ`T%K3l5J[Ry{ϸF[ BFDkg2J3P|.s ؛.Z&tKzWIP amL$+0pQmpobM&'qx2s3ު*wL^h7YiC B]v~HTYzDh8t00EZ9KTZОi@+`9ܠhRՔ>Yxz3[.j0Y+G ֚4Vq$H e~*z-9?z[@.kDS!kDy~>{3{^>^KN<I G8۶=#sԋ|t&a R D}UQ4/k(Ka\? zmĞlh4*݈A'JFbƲU \ǐn".Y\դQWftPV. b%<@KSOC4lI3 jQӷR]7BBr6WFrԵ|ZTqqK \iXO )C' 3 {̔VB~7G n_d;& lDʂR^p@]Hv~ߗыbzQgj6A=yDlX׽P5U&YmMl jW5+v. ]Fs*o7 6.}DOR‰§5oz~;3p;e6V9sN2@cu&)mњK~1'q%/ ( ԼJa?`= :N,4:=y=zٱtbFrcۨ]@][&ҋϹ(FTGw_o+^噲#\({絰xg}^4| ͐sy`\&3ݕAOLӰ$m  95=ȅ~4dv|=4ԮŐp!8j ۥ SXRˠ>h;s+n,i ɘH.sd_ B;Y*F-,2 }G9sI ԧh&llL3 /sg+; ~f"*:c`uC 9}rmQl2"Δr"&{vCineʽ;ehAۿeoXY$򊁹uVنwC Ӱ#G x0tg;-p`NGJ^)X ѵ*B5mF!g #t|[>9㧐|fPv5g( veԠJf$HK H=fʼ""I"y=c*]WoeϋJ B:^STF&.? G;zaUL? ѠVw4>@\=E "96~S˞̷ILA(W͑HZ"49p-exӆ@A <֬>Q) @ UZӘLjy[Q&RT-Y؇tE kW*!ʔn pR_簚}%b"7&6hũq9/d/`R: )gZ93]yy$Mԭu43従EKɈ ۫ `?=Ty[,vrDdP{iY= |]eTך."oX\JdV]ͥЪ{,BDjq lc!g}8 deM4m^X[{V'GWg6#Sد %e~/X"y?Aj"lTg҆lڞgQS $jF9wuML_-PU:> USu+b)0۵61ɖ_0H(C!6E?k8;eahiPmN)z-Ǵ`-jY7mtk z.Ao#QIy8H4dBjg{¯MؒK$F'_y@k-]BIB )8o"h"5c #ck݌kvN1 :Ychp=\paA;"c'\2z+o͒'VF/zqu|]8 ȡ @hlv@`s&,l7(Pe wx?i Xa@HB|́Žo+%y~RZߏ?L3Ɣ1W{z0w#ƪ>ѱax1a=Y~W5C' mYܘ<[tha{)/.@JE-p$=!y>o5NґIȐbʍAuЧJկtP#|JW3*?x&O$CM%|F7<2ϴMA@Qnuܼ@~N9Bυ| SE0ݣFZv!5̌^ %R m~ab$Gήy1焴K~K'dO)=/)xLJIR҇eˇփ{E|w+.w$Æ-JB ,&RSտ(H@;2nr 3C t0ti7Y{Y̿s1M5v_V1aHfq.=y~SAgRB1 6:ܑ 禙"W"$ܑ+PBS(Y3Cv7Er}ΔR%MSUjE}Z{Naט9\NVj%ڍ hSgjT#h@W^U[P7c o%E||+y)>jf.`i##\ӃB>Gn<!ͭ ypCWJ$u)kڟ63`Q_17r2&6z|ppҲv8|oBZ}UU:At%tIdK'n™sG̹*8YDC+^vtJiY[Z,בxbHBfMKO_zhAف~N~ND="=,l3LI|'i=B@S_<`Ⱥ$JQX[Vkld7U6h1`>>`{VmdBQA\X %eB{R v_ qb1}HmNgUN" #KoYi';f0"hΖ|4nP,sc'>i{5_w_J###)czPF`gK\dKǤbdKSp>8ZtkK"_$*QR:a ֘=ρdmt)%OyU~vVsmEm}cahAA g-5#Na3|cYlbDɪÊB=aYfaCsܢv3,wt tPbbqӍ3  ھTڱ Ъ)gӲY3ٍPa̱G~ eMd)Bm]wl3+bͳХ_bvx<+OݒWBa=AuwkH)%y{¢7NH gpeϕ+x# 2_ /5KZKHOs\>/d SV8+T"/Y[wD9J^綖2=ϙ 9du< 'U:c?kh/V]/0#<]9fEz 323ybաTZwRUO#AJy;tu}6?7ҥ$ֱ>J򫠹LZ>aU>.D‹aT>ߧ%\滛@6:#J18yMXxY:{Rl}6!>[*Mo?oǵh ];)I%00,nv]$jq (NA=&aA HfB=ëk!:)9HX3ʊ!b=L\RYbXau+=hOBwܹqpF^Hkk18fϮk7(s"M+f:JgܨH%35sϦq}QY3mIXE[B@Ir`{W`y쓃6߰ DϷHI\RT[nD?f@7&Vpǂd6C:rȡ5N*6NZpF/p6Н@ :ʔZ $zZጓ#^aAyJ±av9|IsUxq64^kmH/$.jmRH\ֹmW -MXu2$$9{VV TĊi^1I5޺0)bR*e \oxg. q'q/C1Rd"[at#ӆȡDܸV68{bYxĮAubtbD~tdmsՆրzT(8l(HSôT }ENDJ("B)hfM;ej -#|y,K,Nb\KSBG߻UNiD,mvZ@(H3Khxuogf<繯&u5mGyiXKs<ȄqўI޿9V8W5xY~^xSl~ĩ<AX-F7\y2GD6c{(: :dX$V%UNoZvG-.a̸{d8  &jA>QN%lk)סH;Wmn ?Ώ9k`TErlY Ƣgd%8s1>e{$ǠqYsCXZl?93v3$ tU絇-lOjᝅEX(0kgnДV)h(׶Lv^>#Et]J72LjءAĔeylb /.OPI 'Y<9CFᘸtA x}ʕSVHE8s9k~4_F!3zMB25^"}U %<aƌ"xu-В86 ETyDmE,J njUguXc3O;!.+yғ&R; qF@t@3 _SqhTI_TY忢2:X{ajR7Cۖo,*_aA]{p7|mT{힬W4hCf=}Vn"p:<% qF:re(g&QE;YϦYQ֢;i |BOۢ O_@i]͉'[+uBl;P73\a*[Ox[-oY? ;dfZ %&E[ ^cQǩ¥Dzbͳ2pywXc!0YRs)mˤϴÀiaCelD+`?Vz򕬪PTc6`vU_[vSyV)·\ 8!<>b[= (hNtn. sn $;4 rT\yi ~1\⩁mM0zA\bN7& '&r}koPWkRaص|rySP73Tv mJd b,mk Zr)s-F(VFILBRWLG`"IsE$\9?g'\92%ocy6\So?n>L R^)leT%1V8b +{Qc/NW=KvIfIg_/ c8,yHLjD].mL;xD"Ǹ],v{ T] }\G{AiWv!#bē?^@Xo."lKqݠ S3Cg(cEt l33~˖FS"`z3X5ʳ(|P Hѕ?g,<l3X~+JI[*[)'*iPrlH#4: TUS%p<;ZYnK)k1wTPoI)vPMȎVzy(+}#Vm"r,l]oQ<|y19!MϚ-IY\7$ZLѨWZT$r73A3\">H"ZNO lfKE ( pUf=V@>-}c!pk#*`B7pQi*N =XYa{HR;R s%/WX']ѳ.|;Ij& !hEڴ,Ty9DooTgEU_5Ѯb+[.O_K$~V *u&"_'+"yy19w\5]sVE ]a`@ܶ&#@1`L3m[sWRE?d8`N̚,.);ɱݭG\JOR_?#bc_Uf>X$$Z +٪E9"Y N+D#= 5hnjM VtMSՉb(3-+Sz(T(O׈V+P heEB)->+Z]XBRS,?'iܛ\rN0O,{3A@[ @ ء6 i@S[h ſ5o&{Y_"9v؃"4xR33xH/Nx4DlA\ws}<fnlXN=ipEYyz*]`"$ H.lo}eYO4z rqU7O{?FY?d\%;?PSFz@_ EQ?~ڌ.n~W]sh|s;5y.}VDmvr%dҫ*Gjhi4p=$V"8!1,|3? 0Xc iqpWEx#xE5pO4&ʢ);%OQ@PΨLP{i>,,r-mQj! {˛9!!GA)DX6*t2@׽/zcQ1{B|\lGRZS.T3ʅO M_WfVTw_A}BtNt$6B -]Y&P7=Fz ")F)mAop$/?,Sw&|3wh1w2&\>V)<+Tyz[>N)/ =: [Gw({ 쟭֥d.A Bl{~NӞk~+-$AN{.(wwd>ϔ -y4U9qVF͔A6ȍ3ar umUy{(,F!B{ɎݱZ{!:`M O>8C{Eir8RUwAED-Է6Ͱ/?$a16dJez^JHt%Iei02؉pp]/[;ܵnk]i~zͤR>Ǖ0@^(oQ$d])~¼)wτ-9x.#*`Z-q$3a[ ^ҔV.81U>ٓF\G΁e/&|vSc~i(LnԏoG_dXCCϲþ+= OPn]6nP6?|Syk(>! I-tOߜXH k)sR+*8blHFtp4fJnJ <ի5Vw-d3C^a3=S&a_@2hl(649oj gv{hP g:>RvA)4Rg[1~RN#~Gj嘹ہulr*Q>}l ~1TQ8ylg=Au!4 ϧ%FWiBhy`P_J`s X%D)_d3`|gKLx J* J_oUBl8(S1Gq- ~ٵڌdvxv»4S1o@Qj Z6OO=϶=yK7GfNr\vU9\$u<7Q,`&?Y.ۓ7`,Ume U3t>F\r$t7C? ՔW'x "DžQx*dGU]>} tU$~˗{%R'H C!;PWY!\>1 ]~}k5]!6bN^xcK[GH D*Ec'#c(g3L֓z+ &b|}e]z7Vm9q@&KJVVLs<[&Lݦ|{@ASa. u?8uidȀ*D,|$;h#hH<m`O ρ}sl" b io5f {Jw¥PA9hz]@kd~ѽd:;&.vOSC |z=18O~ƴ<8W;2QigSm먂K4m| !oTp>->ʆ{UGFAH͉+9 7>-&"uc#o.\t߆*&@#c>c14Rݱ/,qÉ4Y?aQCdTE<$+LҮ fz?6-M1>—5>qN$^E%{?r _<0 Ї^^f'o2DR5av3h?s{|>Vz83= ۃnyjfZU)NY]l}VA8{1NG0)PZn)Ι/_#xn5Bn1T]F!z8:NQKѾnXQkkBQyMxYrekrF??Z!<PUmw{T9$$.O @j'fޅ2f Y<ʳ} 3VQ$zF /'A{w`#ժJt,f eRYoXH%RY'T\23X>~7'tMnzM+ rKe* どs;ܛ1yF]&t&']]rV*h(˞,NzrC&6q,- 9n>`~jEvJD^,$#1l A6 a_I®O ݔ|v$RWNk̤o`ߠ'l`z7>ؖMC3rAJ:;<Ɣ4=F *H.aɶ'.:}Qº[E0U5eXY<G=\nEW;Y_8%㋠6XyP1N++ED{.[`= /R6k:XhS/ʟpYtFaƕ)K:ΖHk|}EՙZ ,g|T)D'dMf Os$µs&r(E8;aӷ|6 (A1{! )]^cR^b2P*%@3%_ZO<&(ؑR{NnUGV7W4EDf@^)NF ,՛A/7;WnB>= LZLggjJY4uHw}!ӐDCKO)|e;zxprc+~z+]-fS+R6^~t*.dǼIe3z*/;Z0Ҷ\XHҳ\0؋Lywv˞ő r]?{NѷAь{9TG'KP^ÉN-tkIlt_pI^)z9϶$- 駈..8M D Q^A!BIM5O֣o-5MkRk}I}[d:G g.w{Y;JXI"^8>"! 9Dų(tˍ+< ,'3Suk(Zo1&Y-`QDӁhG Ic"&ޔaѳҾ;OOMTX0xaq#Ǵ΃ӛ4Ljeep|l`y4.3o7[L\ G:V,!FJ. A  0R><6(S:`wپcG w$̆;IM{Ix5P&HY bgͅ L[qn^tHD佶wQ$$}Y1c|U53Y92&^Kͽp&:Tڞ=رluzOf 2@+rkQTu/R/v~O)ur-J1?iL)XM&W]+@ZʤZU Qp+t1onm(H`=6q*>a.g>D`xBW3{k)Όiʴ5 J'Ǻ'xkQ/jtiiTMR2HS|@H-1u'jY &E+P>0 ?砀c$qWpdVBn &|yV;Olv&V5V~TA"w5{Hj:-XrO:ɮ 4+JsO׫6h|"R]vOv7}ɽ[nӻDAvb Q#}ƀ^@' `V禒w#3D] g068gZ4.ĉĢ!(3}HL$]U 33T g!>_ah3DYgu[CBɻ6Աc?Y90swB]8.`WPj q!G<ܨ 3ZfE:Oew+Nr9 1~7$moCmF2td#_%[[a5U')èr$z$|aY//xOnGkz_ wxpWǗe~j(.[&{l׿݄@T6up0 D-F7.yz#$4GOB%vʈߩ YZ