-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: mips Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: mips Build Daemon (lucatelli) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: 330d1f7a10c5ca52b3f9ebec1ebf2e2deda8e226 2407532 dpkg_1.14.31_mips.deb 224921d8624119e6bbca470389cb0ff3ef4121d2 804382 dselect_1.14.31_mips.deb Checksums-Sha256: 59ed4f37e41d722840966906d8a01669214a5a451eb2176803271c1151ece7e1 2407532 dpkg_1.14.31_mips.deb 67604ff3258a5125c82e0986e74203a95a5130f9f16763dea83f9706648d16dd 804382 dselect_1.14.31_mips.deb Files: 4d62fed12e1b5e802ca643ca5ea0a908 2407532 admin required dpkg_1.14.31_mips.deb c3d2a37bc643f32ce43a2ce7c335c70d 804382 admin optional dselect_1.14.31_mips.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0ksf4ACgkQXm3vHE4uylpzpwCfauUixH4ze6Ua2exkhoKzV+LT hbkAoIEfDV+dPyTzKIdkDqMvWCmcHYao =yfNr -----END PGP SIGNATURE-----