-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: mipsel Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: mipsel Build Daemon (mayer) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: c2a39ee4ad06c4a266752eafb97b7778d00be661 2405084 dpkg_1.14.31_mipsel.deb 63cc3aa0af12fd95633d4bc637ac94755672ae0d 809834 dselect_1.14.31_mipsel.deb Checksums-Sha256: b50a2e531f0fd492657b7960438005eeb773e6a58b43fdd78c769e8396f9bf4c 2405084 dpkg_1.14.31_mipsel.deb 1255bb538a59acec3c914e9d69226bdfb3431496e25bba7fa401263112c26123 809834 dselect_1.14.31_mipsel.deb Files: fef08f4b730cdc276c492084e1768ba0 2405084 admin required dpkg_1.14.31_mipsel.deb eea70ac12e2d77a8c06fbbeb11bba09e 809834 admin optional dselect_1.14.31_mipsel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0ksfcACgkQXm3vHE4uyloYBQCdFUMdzW/MTeyuV4OGkrGLEayX TTwAn2fC9T1QN72aLKmkKq+MEIQ8g5GJ =XEwV -----END PGP SIGNATURE-----