-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: powerpc Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: powerpc Build Daemon (praetorius) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: a26213828830157fd833caca499ddf93b04956eb 2398100 dpkg_1.14.31_powerpc.deb 15608f162cb619c706eb1426258ede3e8f6dab05 812764 dselect_1.14.31_powerpc.deb Checksums-Sha256: fcdbd6ddd2a7f956c6e5791fbcad717498652ffc3eef4988f2d48315b5821fd4 2398100 dpkg_1.14.31_powerpc.deb 6bc008ed25e2d2f8b5a2a0d8e01f11ef6e2a2c7014d6a9b320dff3d470e541d7 812764 dselect_1.14.31_powerpc.deb Files: 5c1d7373851600c0069db97e1660e80b 2398100 admin required dpkg_1.14.31_powerpc.deb f1763e6fc03cbc78fd225af4ac8c727a 812764 admin optional dselect_1.14.31_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0ksekACgkQXm3vHE4uylpHGgCgipjhTTCPNdYBAmtXa8i+LLck ieIAn2ecfTFD5r7B22akN/x4YudNrt1+ =Gi2y -----END PGP SIGNATURE-----