-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: amd64 Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: amd64 Build Daemon (brahms) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: 2ff82bb2b45e8f997802d9bfc74206ff7f5bede5 2401752 dpkg_1.14.31_amd64.deb 49ea2c40071be6420f313bedbd73762760235158 806292 dselect_1.14.31_amd64.deb Checksums-Sha256: bc5fa663afad7801da1695bbe6a3d2aeffd91a9e38f45c886f5bbb35df230331 2401752 dpkg_1.14.31_amd64.deb f36ba5a402d329363e1180dc698bce2f99407b43bff5eb478104fd6d41f1c210 806292 dselect_1.14.31_amd64.deb Files: e3d874a7a6688262cd94577a152e4b15 2401752 admin required dpkg_1.14.31_amd64.deb 3ee3616905003fbfe2ba4cb40f9b8ae4 806292 admin optional dselect_1.14.31_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0kseMACgkQXm3vHE4uylrr7ACgxDmlzNmMMaC+WWjTi0D+Mtak 848An0d7FdP8gV6oGLXcX3v+sSlbJvOz =ZfDv -----END PGP SIGNATURE-----