-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 08 Nov 2019 14:38:14 +0100 Source: matrix-synapse Architecture: source Version: 1.5.0-1 Distribution: unstable Urgency: medium Maintainer: Matrix Packaging Team <pkg-matrix-maintainers@lists.alioth.debian.org> Changed-By: Andrej Shadura <andrewsh@debian.org> Closes: 944355 Changes: matrix-synapse (1.5.0-1) unstable; urgency=medium . * New upstream release (Closes: #944355). * SECURITY UPDATE (CVE-2019-18835): - Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers. * Require python3-typing-extensions (>= 3.7.4). * Use secure copyright file specification URI. Checksums-Sha1: eecfec6d9f33494b50c3af54e7791ea7f5272ab1 2641 matrix-synapse_1.5.0-1.dsc fe83629a6b557da0a4e79992f594adcb3da03a74 1470577 matrix-synapse_1.5.0.orig.tar.gz bab5d3aea02fcd0fc3bf3e815cd6ade5be29618f 89492 matrix-synapse_1.5.0-1.debian.tar.xz Checksums-Sha256: ad707966ea44eb975c2d249e5ddab0f5c7af2ada42eef7bd9a8aee98ca495226 2641 matrix-synapse_1.5.0-1.dsc 62c82fe7ad2c650d9431e6b99cc550f2aa4d0b7fba49da696e619b0b085fde4b 1470577 matrix-synapse_1.5.0.orig.tar.gz 355e9f74e00cfbcede78f168ecbdd973ef266e34f60ed85e63b0cbb9b24d0cf1 89492 matrix-synapse_1.5.0-1.debian.tar.xz Files: cec59a5f641f61a18a0306d644df3f21 2641 net optional matrix-synapse_1.5.0-1.dsc 015c019e97c99af70a5e85bdfc34535e 1470577 net optional matrix-synapse_1.5.0.orig.tar.gz 351c4e1d306b7cf364385361c04e6c57 89492 net optional matrix-synapse_1.5.0-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEeuS9ZL8A0js0NGiOXkCM2RzYOdIFAl3FcIoACgkQXkCM2RzY OdKkqAf7BPkoPQRcY8HpU9VZAXQ9G/i74ooR9tqoCL7T/yLKVrOv0pxzoULDNtpH e0j68BEe2VbAnYxbEEY/DSWsRXKMgNg5NGc099RUnDN17yBKVpOyyk1FLXzU3TMH I0PdY8Pj9Xm619/fMGtXaGq4/gMgmNP1uAWBfMeIBav+BDvUrkn2HlghtXt7e96T aLLGVXCxliEaLdk/ZUwq9OuWIsBoownC3LAM8R2E/mw33ttAu97NgXmQz2mKVX6N 4KSALE6i9wifTafdM9AL/QSKG5Ps75qZcxbQG4fu++GfP1Uu4SRFFszLJm5MN74W 4EezgJ6dsn4LN1EbN0GyS20MuyWNZg== =FoeW -----END PGP SIGNATURE-----