-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: alpha Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: Debian Build Daemon Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: 810f45bc57aa19549b0e1e22fe6daef5b5261d57 2446720 dpkg_1.14.31_alpha.deb 7cb285b773b3873ef36e747cc0b7a79e57ee77f3 814638 dselect_1.14.31_alpha.deb Checksums-Sha256: 159c3379c2bcfb447a7362fe9c9d71164e12b53b9afd5675570d60a9d3132088 2446720 dpkg_1.14.31_alpha.deb c51232d3eeef1c4075c3c3c8cd1bdd86963073b01e6e689323ce552c31174686 814638 dselect_1.14.31_alpha.deb Files: c2c52c5131124e1b62db5c94a2b84a1a 2446720 admin required dpkg_1.14.31_alpha.deb 3e50f59cd0fcfa4a30495aa81c18e107 814638 admin optional dselect_1.14.31_alpha.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0ksewACgkQXm3vHE4uylpdrACdEjQoEgmfJBemA58TIgDEQfhy X1oAmwQZ9Nju6l72qZAkms6/ySEX7VBR =Rb/h -----END PGP SIGNATURE-----