-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: arm Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: arm Build Daemon (toffee) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: 8f995308d384b0c5b734660e48f36ca7c48f0fcb 2363080 dpkg_1.14.31_arm.deb 4de703ad8bfc606721d06062d5d4b3e8efd586ae 792790 dselect_1.14.31_arm.deb Checksums-Sha256: 592c8f2203501d5e9e8f092157cacaab2a64dce441768f7a5870a83da1250bf5 2363080 dpkg_1.14.31_arm.deb 3565c2506d3508375a4f90dd7d9af16b72c7261befe6805609920d6e4f488d9c 792790 dselect_1.14.31_arm.deb Files: d04d93bfea1b01a03f5be454f147f71b 2363080 admin required dpkg_1.14.31_arm.deb dffbf33b96dd7ace203b1103c79cdcc3 792790 admin optional dselect_1.14.31_arm.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0ksfwACgkQXm3vHE4uylpluQCcD29bP1bOOkjYLd8z/KW2QwGi G/8An1XKELwvW0etv28RPL5OeRdDr3k1 =nhHt -----END PGP SIGNATURE-----