-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 05 Jan 2011 10:58:17 +0100 Source: dpkg Binary: dpkg dpkg-dev dselect Architecture: sparc Version: 1.14.31 Distribution: stable-security Urgency: low Maintainer: sparc Build Daemon (spontini) Changed-By: Raphael Hertzog Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end Changes: dpkg (1.14.31) stable-security; urgency=low . * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: 8fde503e094f5206c9e10d19a1fa8da84ba685a2 2358576 dpkg_1.14.31_sparc.deb cfeef4025367c2ee9af04c89d6eba51dea0769a3 799098 dselect_1.14.31_sparc.deb Checksums-Sha256: c20ccacab109addc4ea93d63849ff98ff7c9ffdf5fde851082219627b8a93b72 2358576 dpkg_1.14.31_sparc.deb 20be26dbda65a5f762323ed30effb6f1a63544ef088098ada8b553a2d3568c31 799098 dselect_1.14.31_sparc.deb Files: 468ec88c30428b6fadfac9684d951910 2358576 admin required dpkg_1.14.31_sparc.deb 76d0481936ef489d1359c74cc860c2bb 799098 admin optional dselect_1.14.31_sparc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk0ksfkACgkQXm3vHE4uylrfZgCgyMs4vs+m6Fjf8z3u09gWfBGr eAoAoJa/KUBj9OeCEgrBY/guGdepbOli =DfzV -----END PGP SIGNATURE-----