-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 28 Mar 2015 04:22:18 +0100 Source: arj Binary: arj Architecture: source Version: 3.10.22-13 Distribution: unstable Urgency: high Maintainer: Guillem Jover <guil...@debian.org> Changed-By: Guillem Jover <guil...@debian.org> Description: arj - archiver for .arj files Closes: 774015 774434 774435 Changes: arj (3.10.22-13) unstable; urgency=high . * Fix buffer overflow from size under user control, causing free() on an invalid pointer. (Closes: #774015) * Fix absolute path directory traversal. Fixes CVE-2015-0557. (Closes: #774435) * Fix symlink directory traversal. Fixes CVE-2015-0556. (Closes: #774434) Checksums-Sha1: 57ee5fe96805c416050fd806686c995b1b8799d9 1845 arj_3.10.22-13.dsc 43dbf02ffbcd78a1d408215f63dbf7209eba9634 15904 arj_3.10.22-13.debian.tar.xz Checksums-Sha256: f21fc0ac96208eb0a241dd6a64297041799dfe03a10ab55a4625690efd5ae58e 1845 arj_3.10.22-13.dsc d74588f13a2de780d762d3405b0216a02cf4e55bda4ac4703cab94310ac3ea46 15904 arj_3.10.22-13.debian.tar.xz Files: b275600afa1d8303fd2aaeaf1ad218af 1845 utils optional arj_3.10.22-13.dsc 2623eac2713d5d0d116261c1cf707dc8 15904 utils optional arj_3.10.22-13.debian.tar.xz
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJVFidXAAoJELlyvz6krlejBV4QAIot49gZCXUFqJ6GgxnVlptu dtaH0pdayH3LV3JbgifMEM3cmYiyi9TDipFKTzXK4Od8kWkUDROt583eNUp56R9e fSgAPWrUS7yEuj4X4GYP0VvHEEQHaE4IX7XBC3R6/T354nICQ7hMi8gqi6oBnA3T 04ZzS0hNPkZDYpmqEvxRHtGW6egVEJQJV6YDN3HOuocTD8lDgTbwpNwPsC9gjMyM WECc+gdHSMlYBQAZxK8n/jsIfR8C1o4dJ0ot/VGgpN45rCG/fh+ogqYMliDP3T2Z ZO4iA/q9QkmotNLCFa1+EExg0wMLou4eSY44Te2F4gmbv62jspcdu04OSHvnninv h2/Y4aJGn3uJduF9/17ME77mJsCZcWxMeIB56G0L1wDjz9E6LJodQbF3qMFDSPmR yYoONhTdRMFTJ4nLLpgapFZKAVvoSR3hLUpt9dy+RVyrPLmlOH48AhXZtfWuaiSB cK9dBcsrcLhMRY0sPKedc45TXfAm1MishIMRo56QOt9cZgRKfchdZ06BTt/Q6HmO j4sE5OPPgK2zNIT7QRA8o4qfGQrazZAmqVPtPyqJmw5UXa04Q4fMKiVh+JMA/gIC DAOkW90RlHI10/k08RbFJhZPFbNSeCnWUH3oEjEr/E19H951UyMizOxQo1K39KSQ yOp9s5vHAYO65Apj9BXJ =bX23 -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to debian-devel-changes-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: https://lists.debian.org/e1ybidl-0002y2...@franck.debian.org