-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 07 Jul 2019 16:11:38 +0200 Source: dosbox Binary: dosbox Architecture: source amd64 Version: 0.74-4+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Jan Dittberner <jandd@debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: dosbox - x86 emulator with Tandy/Herc/CGA/EGA/VGA/SVGA graphics, sound and Changes: dosbox (0.74-4+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2019-7165: A very long line inside a bat file would overflow the parsing buffer which could be used by an attacker to execute arbitrary code. * Fix CVE-2019-12594: Insufficient access controls inside DOSBox allowed attackers to access resources on the host system and execute arbitrary code. Checksums-Sha1: bdf382d71bc19177b8ee16715164e1325d1f44c3 2084 dosbox_0.74-4+deb8u1.dsc 2d99f0013350efb29b769ff19ddc8e4d86f4e77e 1265711 dosbox_0.74.orig.tar.gz 60504d3f51bf6da2d142f486368de7ff4dfc758b 89604 dosbox_0.74-4+deb8u1.debian.tar.xz 5aa62bfe2b22d8906c42734712de7cbfa0fa3907 856084 dosbox_0.74-4+deb8u1_amd64.deb Checksums-Sha256: fae54ef4f103655658de5e907bd3e68a990c87c4188791194eb8ec11b52e91b7 2084 dosbox_0.74-4+deb8u1.dsc 13f74916e2d4002bad1978e55727f302ff6df3d9be2f9b0e271501bd0a938e05 1265711 dosbox_0.74.orig.tar.gz adec00e5819ec32f288bfd651cedd0a6efe44b0febf0efc526c6ec2a01906d64 89604 dosbox_0.74-4+deb8u1.debian.tar.xz 21dff1311073e3d16b02720a413e89830aca2a18b32f95b872fee4a47e44db01 856084 dosbox_0.74-4+deb8u1_amd64.deb Files: 96be28835bf8f93d6366cc4c89c23f81 2084 otherosfs optional dosbox_0.74-4+deb8u1.dsc b9b240fa87104421962d14eee71351e8 1265711 otherosfs optional dosbox_0.74.orig.tar.gz 75572d076a55b60892d66ebbca453ceb 89604 otherosfs optional dosbox_0.74-4+deb8u1.debian.tar.xz 9bd499a7f89a92657e826531727338ea 856084 otherosfs optional dosbox_0.74-4+deb8u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl0iDKBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkjyAQAKfFRei6RooIUcYLP4+V0IeIUaJaWg8O6Y95 +Vn8rsfK8yxWtxHu2sC5k2Lk6qlQqn6l3jtlRw+6+hWfO8TJj8Y1nHC8l25kRHSP eAMM/py4wfpGiUknNtXG9RwSFhxlLdRpXazlJ3UuiAAdoPR71e/talM2qiRzFFkv Y/f5mkF/6s173S/JaMCCjW3I7xiC0xQ1gqoQ9SN/H8lUwDyYtUKuFJNObjymFleb lAwCt1/pa3PCsT2tP5khP8PSz4VundgndnnWxEvAGUmPjxkHN1jia+Cz+cTAv7cv lg0dUE00IrbB9J67DEWKXWZovav9RKZg5EWuCkKRbMR50TlGcInvpMKljouBIns5 SU/jH09sT2swYFQjQPjdip5rFPYWZTYYKP//4As11NQ38z7lr26ZD+JcrNsRwR1i k2CdYdz1R4pHR4Cz71RRv9siZTvmyFTM+XQbvn5QdiJNxRepyUp4/llyN5Fgvr0n ClkZaeGB0NqXopPHy7NdbhfcY/IL8j7fGvzLqB5q0UNYRAYYkQ4vB90pVP54PSsJ Uc1mbUfNtouck9ks47pfQk4RkIZWBlsbiAfzM9g99z9U5+ZQTWQoEd19ddYUUtZV pblJq74LLkAUCOVVSDGpKa/HCdnLAPCKwhAVq9OLsaSD09vns6LGMKwVwZYnvb11 xNENCmor =qOT6 -----END PGP SIGNATURE-----