-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 30 Jul 2019 11:41:55 +0200 Source: matrix-synapse Architecture: source Version: 1.2.1-1~bpo10+1 Distribution: buster-backports Urgency: high Maintainer: Matrix Packaging Team <pkg-matrix-maintainers@lists.alioth.debian.org> Changed-By: Andrej Shadura <andrewsh@debian.org> Changes: matrix-synapse (1.2.1-1~bpo10+1) buster-backports; urgency=medium . * Rebuild for buster-backports. . matrix-synapse (1.2.1-1) unstable; urgency=high . * New upstream release. * Drop an old patch. * SECURITY UPDATE: - Prevent an attack where a federated server could send redactions for arbitrary events in v1 and v2 rooms. - Prevent a denial-of-service attack where cycles of redaction events would make Synapse spin infinitely. - Prevent an attack where users could be joined or parted from public rooms without their consent. - Fix a vulnerability where a federated server could spoof read receipts from users on other servers. . matrix-synapse (1.1.0-1) unstable; urgency=medium . * New upstream release. * Refresh patches. * Make most runtime dependencies mandatory. Checksums-Sha1: 9742d40bfae37a31df602c70fd13d2e83d804cc7 2643 matrix-synapse_1.2.1-1~bpo10+1.dsc 9b23c7896ce15074ba8f64cfbc498e888185318b 89776 matrix-synapse_1.2.1-1~bpo10+1.debian.tar.xz Checksums-Sha256: abeb0b81a8ff38321fe3a6e77dcc157e1683e85a213eea73461b80cffaf6939e 2643 matrix-synapse_1.2.1-1~bpo10+1.dsc 61fd422c4e07df7b8ef90be1ca05d2bbe25fd6192350af5888b44b91adc64e14 89776 matrix-synapse_1.2.1-1~bpo10+1.debian.tar.xz Files: 5eaeb60789dca65fd47a6c7ccefe401e 2643 net optional matrix-synapse_1.2.1-1~bpo10+1.dsc 5f84937a56b60c872b83f96631e3109e 89776 net optional matrix-synapse_1.2.1-1~bpo10+1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEeuS9ZL8A0js0NGiOXkCM2RzYOdIFAl1AEWcACgkQXkCM2RzY OdJaugf/WE38MRkH1aOgAnhC5ZYHCM02nap3rZ1sfGzba+35BiyDLVUGzFSnKlCr 4MPGg0ojb62oQfvkVkSf1RxqvJjlSGinICh0BuawWHRcDqgVBbok0mr12EpwHGRh 9xLlMNwJZ1CAPut68tLi9r4s7pzfJPGeSURahT8sEMEl6msGu6DJlzSZWNqVqdW5 GOzvYYH8cEcqA/WMHz+qffV97dKGkpAIapkF/fyDxqbKDT1siloGyIjUxk5i4fYL QgnMOBhYFqFBvGmbRcx6RRuciy2jNsOnw0mVr/aQ17em96MMjC/+a+HC/YliP2vF fHj0CLyLp7nCxVsgulJ+0GbuYb2fvA== =8wUB -----END PGP SIGNATURE-----