-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 17 Jun 2015 17:04:10 -0500 Source: drupal7 Binary: drupal7 Architecture: source all Version: 7.38-1 Distribution: unstable Urgency: high Maintainer: Luigi Gangitano <luigi@debian.org> Changed-By: Gunnar Wolf <gwolf@debian.org> Description: drupal7 - fully-featured content management framework Changes: drupal7 (7.38-1) unstable; urgency=high . * New upstream version * Removed patches covering the differences since 7.32, as the freeze and release are done. * Several vulnerabilities fixed: SA-CORE-2015-002 + Impersonation (OpenID module - Drupal 6 and 7): CVE-2015-3234 + Open redirect (Field UI module - Drupal 7): CVE-2015-3232 + Open redirect (Overlay module - Drupal 7: CVE-2015-3233 + Information disclosure (Render cache system - Drupal 7): CVE-2015-3231 Checksums-Sha1: e4db61ebccc4470fe62f769afcd22728dd94d770 1869 drupal7_7.38-1.dsc c83a03dceaf7ad49ed60fbdbf24f23cc2cea1526 3241755 drupal7_7.38.orig.tar.gz 338d7b8b82292cafdca8486c30b8700f46c83b9d 173048 drupal7_7.38-1.debian.tar.xz 3fdfed9070d21aa56895041f57b8263d5518b7b0 2484452 drupal7_7.38-1_all.deb Checksums-Sha256: 9d535b45595737452a4f2407624c51987a2848e2b7163a155b8d618c55b03d74 1869 drupal7_7.38-1.dsc 1beda3333e384ece64894eff356ccb75b06081200026841babcf43564cfe4fcc 3241755 drupal7_7.38.orig.tar.gz e75bdd6114ec03518afd706360a4a3eaa6a29892705d7545ba02fb0c3d40f01a 173048 drupal7_7.38-1.debian.tar.xz 90a95e52b716f36709e3b595f2528b8583a8b5d737e86720b1a4416d6ddfeb63 2484452 drupal7_7.38-1_all.deb Files: 05a9483d0f725bd2265a61ee77406338 1869 web extra drupal7_7.38-1.dsc 56cfeb770bea476fa9590a6a0acb867b 3241755 web extra drupal7_7.38.orig.tar.gz 9b5074646a0562f98e949e2aa2a0692d 173048 web extra drupal7_7.38-1.debian.tar.xz 8fbda2a3478cd5f02bfd1738655b6236 2484452 web extra drupal7_7.38-1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJVgfDLAAoJEGc6A+TB25IfDnMQALxbZvvyXzet3oWewO++gi2F XLp+RZoy0wOXyG9bkgW/vXH+NenzAygZNgHkQwetLJzTWsfzTrBkJKnM7Xu7zodo ZRUSj9llXanyo0/g1YNSWiZEngR/I9hGRnyf0+2aqVc77MNF7UDNxY4b9nrg5x+7 jAWCHDqTiU95cfr0Fe0DwXruKVq72qhrE6Pg9gbAv44ThkMD003qwjXtTusYxSIn PJ1HW6R/N78HDXQRT1g0DV4kOC+nOrpspx4/RnB1zzlLHr067e2o+/0JGLz+r4AA SuEdgODBiUmm105bYNg/eCC86YDyGTzmyjvysh11khNHYBSIBi5G8m88MfscJzmT XdwVko1RR9pC2kFfcNQKtBVT/KzU8f60T6l/PCz40lOsvWdr8d/XAA7v7cu30qzH 0KqekXvcwiAN4Tj9M3Aj88xWNQjRC/Imn8OFxWOFP2TzpxjxgzgrRXOd+FU+zCr4 awm4pD/dBib4SaSVdRxW5NsE8fV9q0ma//MMxYoqxGUbcNw5JwVM0HXqZoqQeqZ2 CVdrcbkDcp4eLSEMOTAQ3Edlr/usZ8wBRZYUsKbKCQV4v1xCUHfWPZ9q/fOOXm8w FbPvDt72UA5cL+x7tFIDOWe+OkgMmfADEJ8yCmCc/51WZKPwbQAj96QNzNbKgzGj yC0Ge1lYPORnpSErotzQ =+rST -----END PGP SIGNATURE-----