-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: armel Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: armel Build Daemon (alain) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: 956cf97aaf28244b13479c2a7c895d194e081501 2362648 dpkg_1.14.31_armel.deb 076e1752c5616062225e191f254574dd89e2d251 789676 dselect_1.14.31_armel.deb Checksums-Sha256: b2f7cedcc731638523a146356f2e7348215d2f1019b52d83c2f96e764b31fc00 2362648 dpkg_1.14.31_armel.deb 0ad2c2a351772013656958896594fd419a7269aa066bddc6126abf740d110036 789676 dselect_1.14.31_armel.deb Files: f9ee71316051714467fc9481dd9b43c6 2362648 admin required dpkg_1.14.31_armel.deb ab53a4b7c0f45c3166ce821815de1e91 789676 admin optional dselect_1.14.31_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0ksfEACgkQXm3vHE4uylqPmACgsyAtMJurECMZ4Dluf1+/QlfI 4IgAn3eNCf0+BNaaPxFhEf0lEojQt/MX =dp70 -----END PGP SIGNATURE-----