-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 31 Mar 2019 17:45:52 +0000 Source: obs-build Binary: obs-build Architecture: source all Version: 20160921-1+deb9u1 Distribution: stretch Urgency: medium Maintainer: RPM packaging team <pkg-rpm-devel@lists.alioth.debian.org> Changed-By: Héctor Orón Martínez <zumbi@debian.org> Description: obs-build - scripts for building RPM/debian packages for multiple distributio Closes: 887306 Changes: obs-build (20160921-1+deb9u1) stretch; urgency=medium . * CVE-2017-14804 (Closes: #887306) - Improve extractbuild to avoid write to files in the host system. - debian/patches/Improve-sanity-checks-in-extractbuild.patch: add new Checksums-Sha1: 6aa69d78370f745beb8fbc56f6a35eb007aed0e2 1896 obs-build_20160921-1+deb9u1.dsc 2c361070549903e36e4dc95706c1deb9336bc34f 4548 obs-build_20160921-1+deb9u1.debian.tar.xz 417abe74097c6211ff9b06e0f96806a0e992a7fe 142186 obs-build_20160921-1+deb9u1_all.deb 41f0f7f260e328969fac572edba563144c623677 5748 obs-build_20160921-1+deb9u1_amd64.buildinfo Checksums-Sha256: 81bf2e2350edba0b3c6792daed3e864e0365f223d1fe79d056257537a89f9214 1896 obs-build_20160921-1+deb9u1.dsc b30d9168f8c61d0c008f1d39d80d669b71dd616e33aae71dfde17ac6cac80885 4548 obs-build_20160921-1+deb9u1.debian.tar.xz de27c65cfb05fffe3a07cd4878c70f68898e533e8cff0c652ab0340aa7726ce5 142186 obs-build_20160921-1+deb9u1_all.deb dc4a84d0b11afb3e98d1a8cddafac633cd936b09c508792633eaa4c2c485e17f 5748 obs-build_20160921-1+deb9u1_amd64.buildinfo Files: d110da11406480a4a6c42d3bc70de3e3 1896 devel extra obs-build_20160921-1+deb9u1.dsc d1840ab930eb4070d0171a1f9657c345 4548 devel extra obs-build_20160921-1+deb9u1.debian.tar.xz d6bc2ffa167f9ecd769ca25f39bba248 142186 devel extra obs-build_20160921-1+deb9u1_all.deb 71a0d144da41a143fbbe1a0ba86ae8a3 5748 devel extra obs-build_20160921-1+deb9u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE6Q8IiVReeMgqnedOryKDqnbirHsFAlyg/qUACgkQryKDqnbi rHvwHA/+J3P3R4xLEtITNJnCFyW5ENPGom/xjqyqBHR6O2ccjYMMrhyKi23tXuKR 7E3NgyAz+NeK9AeK4pGpWtkOQ14ZT04MOZRSsW8cSdqg/ckBSDsYA0EWJL/AArD7 QHYas7G9va/p4IFNkjNWD2LEUp7I+a0viZUUwV7DPQECyof4CXLoEkugEgxjS92g DbqNhBRFtcTVuvmSs69tAxA/GPm3UkoZVTbp2/itTLSOj77xk3ItSjJfcn+Tyv4y 0E6J958Cw68R+aJzZ/kIaCUc/h4eRZuDfXiV9d3yHDpF+premeu7NKuembI02QNx do3iZ/M2movj5OWRXbF96c9uTpSfZMFffN6RQwLTSUp953s2pvo5lDH0owrBo0/F USsq6ohNgLq+gZw5+laJgWkvDG6MmV0+N5KPd67C2ANuQMdZpwGvAPynaDp80EHs TCJJPoMOhtHRbKjw41IQn24QiJtrF5kytWAnyqcHOrLNMD8C1eoHyVibESiqWp7f F2rI/QFqihI1/BifFlCGUVuOaphw6bt0uZqm/gIKJMtOQeQJuHRrEOIfJxfz3O0n SiId9JQbk0ocW1EAx3wWtVjmhlNKXiKDVBt6m6d/pH/JERN/SzHhHpmHtB9ih8et A6HZ5/OgbdDMa7JbpLdV1DYg760Oo3tCnteb5aJTpGHOqGlE4lw= =PQf7 -----END PGP SIGNATURE-----