-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 08 Jul 2019 08:53:37 +0200 Source: dosbox Architecture: source Version: 0.74-4.2+deb9u2 Distribution: stretch-security Urgency: medium Maintainer: Jan Dittberner <jandd@debian.org> Changed-By: Stephen Kitt <skitt@debian.org> Closes: 931222 Changes: dosbox (0.74-4.2+deb9u2) stretch-security; urgency=medium . * Apply upstream fixes for two security issues: - CVE-2019-7165: long lines in batch files would overflow the parsing buffer; - CVE-2019-12594: programs running inside DOSBox could access /proc. Closes: #931222. Checksums-Sha1: 78a77203947225bcf2d88e1917b242d45af69807 1941 dosbox_0.74-4.2+deb9u2.dsc 2d99f0013350efb29b769ff19ddc8e4d86f4e77e 1265711 dosbox_0.74.orig.tar.gz fec2d24850ad873ceda2bad68d67a2eac4e12a93 95524 dosbox_0.74-4.2+deb9u2.debian.tar.xz 053c0d45fee3c8fd703dca28eafc2d9ea841f39b 10360 dosbox_0.74-4.2+deb9u2_source.buildinfo Checksums-Sha256: 1fc34248fcb56f5423b747e732e7d743c9b85c5fca85c4e409e5d6a96335d4ec 1941 dosbox_0.74-4.2+deb9u2.dsc 13f74916e2d4002bad1978e55727f302ff6df3d9be2f9b0e271501bd0a938e05 1265711 dosbox_0.74.orig.tar.gz 9cab0ee4ed1d5e1ff8e31bfc569d20382d3fed0dc75bbfaa4a0a5695015ad34b 95524 dosbox_0.74-4.2+deb9u2.debian.tar.xz b11d772ed090cfbd6d5d7dffd40f584411d80d02ee1273de09ec8148564e5ef1 10360 dosbox_0.74-4.2+deb9u2_source.buildinfo Files: 95497978547768448ca53d2bec78c5a7 1941 otherosfs optional dosbox_0.74-4.2+deb9u2.dsc b9b240fa87104421962d14eee71351e8 1265711 otherosfs optional dosbox_0.74.orig.tar.gz e487cc6eba6a0a84a5c6880a634742f3 95524 otherosfs optional dosbox_0.74-4.2+deb9u2.debian.tar.xz 1f5dfc04c8e36c33b4cd60a2f12e32ab 10360 otherosfs optional dosbox_0.74-4.2+deb9u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnPVX/hPLkMoq7x0ggNMC9Yhtg5wFAl0jLUQACgkQgNMC9Yht g5y0Ng//RH3pQOwIzue6ItLP6FBjGILOtzdEm5DLjSx46u/2sZ0v6fP9zXdIGmZh ixZRWNLJV7lgFXdHX0vJNk3XG5WYjS4/FI0ThHbCdA5d9+XlvzqWLKD8fijuP7H9 U/T37Q9EpqZ9WP2Ej1R4bWq3NV0vPLUi7D356jR7ViQNSKYX1FaXNcr1ldfYhB1A rgjLOup4JI1XhcKW1LMTX93Ot8soQY4+FjV2Z0bfl7IDl1av3RYgtbdiKtjIk9u3 yhYSCT3zfSFdYUwUzvTVSzYcEuhQPYuEq1qFbSLJ6kZSjydhbk60GxHOch92w7Ue l47kPsVkjrAmcj/a82MCdkWh6D+nmfeIjRxqdC1GONQBWVY0s3zJHpH7kBjQG95I TK67fTFQHFkuPkmCq1ng7PWmJ3T77sYyrUn3JuGrRMalONgcv2/KaA0o/YFKOjZV yVNPvj/Dmmtbz/YgHgdxapnBqMmPYQ9IZl1Win7fJNp/6hbdmo9h5AxcHZ+QWTBL IfDZ1DJJ0ByrGEfk09tGMyKMTQbtCUJq7TvaTQYFycAe33ydXQ0JdScWidComZ7X 9f4JQ3Hymb8MAYNlALgclWU46UMXSOLHV5HM81ptBAqsU/AWkJuhP/n0H0A/b+Bo z5dAnMJ9iVjE46Q9mAQ8MB4C7Hhjh8wq52DzGsqCadZNr1sVOWo= =ppOe -----END PGP SIGNATURE-----