-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: hppa Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: hppa Build Daemon (peri) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: dbf26047dfd283e09cccd713ba6d248557eb3ff3 2413912 dpkg_1.14.31_hppa.deb ca7a8599dd6c1d256ab77b393625dec0e55a6301 812036 dselect_1.14.31_hppa.deb Checksums-Sha256: 21e06fcdb5810f4871d4eeead36c41b7c72ac1e343b08f9ac524f4f24ff3160f 2413912 dpkg_1.14.31_hppa.deb 626ab0b44c03f09d72cab88c37fb324cf1c4065cc0aefefb9bfdd06a441b2f13 812036 dselect_1.14.31_hppa.deb Files: adbc9287e79bd2d783e30ed839f20f2d 2413912 admin required dpkg_1.14.31_hppa.deb 0ba1219dc33effd8a6cfd9c1921ce1b1 812036 admin optional dselect_1.14.31_hppa.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0ksfMACgkQXm3vHE4uylpqeQCg4TBOYqKWHGMNg7afr1E5UQd/ 2VgAniT4q01YrGjQe1uzcV9b47MECg2P =WxqK -----END PGP SIGNATURE-----