-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: ia64 Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: ia64 Build Daemon (alkman) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: ed0ccdb3dc3f38e00926f3cb4d2c7019ac29a2ad 2606886 dpkg_1.14.31_ia64.deb c897b0ad233339639376fe5afc1db079a41ef83d 843120 dselect_1.14.31_ia64.deb Checksums-Sha256: ef3d79707135124b4d3b02e60f3b7864efeb97e3e81394cddba0661bc2286f79 2606886 dpkg_1.14.31_ia64.deb 1bd0401fcb13a7f9aceb6876de7ac6f67cdfb701619cf69ecb0e7d325384ee7f 843120 dselect_1.14.31_ia64.deb Files: a421f730a342f4e8b9030afb5e60596f 2606886 admin required dpkg_1.14.31_ia64.deb 99ab11dc4bbc7dbe4f348e22dd341b40 843120 admin optional dselect_1.14.31_ia64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0kse0ACgkQXm3vHE4uyloUYwCglRqAaqgWgsOVaLn7coRpOOp1 FLwAoL/r6JpPqKNR2/4wqOWkXaCPLvsu =+XWR -----END PGP SIGNATURE-----