-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 31 Aug 2019 16:09:11 +0200 Source: gosa Architecture: source Version: 2.7.4+reloaded3-10 Distribution: unstable Urgency: medium Maintainer: Debian Edu Packaging Team <debian-edu-pkg-team@lists.alioth.debian.org> Changed-By: Mike Gabriel <sunweaver@debian.org> Changes: gosa (2.7.4+reloaded3-10) unstable; urgency=medium . * debian/patches: + Add 1047_CVE-2019-14466-1_replace_unserialize_with_json_encode+json_ decode.patch: Replace (un)serialize with json_encode/json_decode to mitigate PHP object injection. (CVE-2019-14466). Checksums-Sha1: 0b706261d894121a6f41a3a746dfb39962ff171e 14333 gosa_2.7.4+reloaded3-10.dsc 93605a47f5d3d88a11004d79d8a9e87574143c27 98344 gosa_2.7.4+reloaded3-10.debian.tar.xz 3d52c531d8232d6072bf4ebf3335784b7bc2f6c5 7175 gosa_2.7.4+reloaded3-10_source.buildinfo Checksums-Sha256: 5fb28601db47f061458fab296452f7ebcefe2ff798604141d257a393da7770fc 14333 gosa_2.7.4+reloaded3-10.dsc 5579a25587f245fc12ce075546d2cf878969e2771e269ff93470bc005fc06ce9 98344 gosa_2.7.4+reloaded3-10.debian.tar.xz c586b7ea66b5606df068f23bb807c11924e0049ea2f146b155204349ff56a303 7175 gosa_2.7.4+reloaded3-10_source.buildinfo Files: 723e7b5ec820cc88b6aee3af34d56435 14333 web optional gosa_2.7.4+reloaded3-10.dsc a46881e1e913722ca7189c698bcb6584 98344 web optional gosa_2.7.4+reloaded3-10.debian.tar.xz 4e4dba813aba03a0f177f3a0eb4fdcf2 7175 web optional gosa_2.7.4+reloaded3-10_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJJBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAl1qgA8VHHN1bndlYXZl ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxSjkQAIipMue+2rH5lEv12Afit9rj0x// yNs68xP7HH+uFuE8ix+6+YiCQAcywNaYeWU1N4JTmjEJXNKPFEivSXPHcvQ1Cc9S 8Y1Q6nuYl8lfZynvUIvDZnhlZeB+ZWFRvWhC4kGrkrAyqYYA/cxvPvOSjphJAgl3 oiy8jWIvu7SErlFWyh/SyCuwdXSJtYsSN9WU2pRoP7Q4VXTbDzdGUfeYdoyh91Uv 6EVHMwl0LM6Pvm292RbHEXBxSrMWxoeb7ku4ulk0OqzoFifACOKBpmk6wYlqShQK BS0ak/2fTN5a7OrPfcEHcZWTACFiOdFW9rKZkhS2L4ztNR/OJOyGilo19acm5zuJ dTIQQkkrlxMgyXyzptOFkDMwZ4ZffJzdajf3c0Tr6h4Fh5w3Vph9Q/WLyT6jJeJh ckAVdMhRScSBpy0+aqDZ5AW26WZs6KwMpqs1mkE5LsR5vh8w8hOW2mg6hhCEojlN 4M6SEDuVNC1vaDLdrjAsMQ4mQtve8kTbvqPjU7Zm6s2pb8+kq5ySuuf5+m9ET3Uu 1s52NUlDFct06P3scxu70BYIgMtYMjhzvjvW1IGYkj1TimVl+7JU0XuSysPuUKr3 OyCA10JQH3a4aB0sBcwB+JGMfm9cFg196dhHLn/GeukEydZvB91HbzVmqbsNb00c VzzrclD8BZDcJCXB =HM3Y -----END PGP SIGNATURE-----