-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: s390 Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: s390 Build Daemon (zandonai) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: 4f05085caed255410dbc1fa980f27b016b9dba74 2410210 dpkg_1.14.31_s390.deb b7f0fafb940a48ed185bef9b7bc23f26a71da1c0 800870 dselect_1.14.31_s390.deb Checksums-Sha256: 655eb1aaec1690078e4d1e0ee7e3a72e0d5fda61644028eecf277605383e5cce 2410210 dpkg_1.14.31_s390.deb b81a9dfb08466231072c5d7b2478faa0439e8b6a59f0a9dc83822c0d7e0c5f19 800870 dselect_1.14.31_s390.deb Files: c74efde92c6fbc7a05ba8e2cf7468f2d 2410210 admin required dpkg_1.14.31_s390.deb 8be258254e5e27e15c8e083eeffaaec8 800870 admin optional dselect_1.14.31_s390.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0kseYACgkQXm3vHE4uylqvMwCg1kzP7WUJVpOux/ygmX8fHFae KmkAoMebgqoaXaIFpN2xg2jnQh1/5Xl7 =Ro7Y -----END PGP SIGNATURE-----