-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 24 Mar 2020 13:48:19 -0400 Source: php-horde-form Binary: php-horde-form Architecture: source all Version: 2.0.8-2+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Horde Maintainers <pkg-horde-hackers@lists.alioth.debian.org> Changed-By: Roberto C. Sanchez <roberto@debian.org> Description: php-horde-form - ${phppear:summary} Closes: 955020 Changes: php-horde-form (2.0.8-2+deb8u2) jessie-security; urgency=high . * Non-maintainer upload by the LTS Team. * Fix CVE-2020-8866: The Horde Application Framework contained a remote code execution vulnerability. An authenticated remote attacker could use this flaw to upload arbitrary content to an arbitrary writable location on the server and potentially execute code in the context of the web server user. (Closes: #955020) Checksums-Sha1: 8f4a5dfaee667062c9c17d331b87a32fc8187c67 2031 php-horde-form_2.0.8-2+deb8u2.dsc 8f48183c3cd0718e92c656ce1bbcc8a7b1548b7b 3372 php-horde-form_2.0.8-2+deb8u2.debian.tar.xz 0d50a94373ad962dcc31b902925db8a07f253c6e 138720 php-horde-form_2.0.8-2+deb8u2_all.deb Checksums-Sha256: a770fcc0fa38f3ba0490981bf859baa4001163a8ccbac588db5e9c7fb89ac623 2031 php-horde-form_2.0.8-2+deb8u2.dsc b1a5c0d3c3bc4f2c904f6ef3a6f07e95de4f644267067245ee7d342eebc8e6e0 3372 php-horde-form_2.0.8-2+deb8u2.debian.tar.xz 41098e8a3aaa3ccc98ac1d7efa23d132a73776cdc810cb870a74529a57176d20 138720 php-horde-form_2.0.8-2+deb8u2_all.deb Files: e3d2d8feacbe604ce0579fcc13171590 2031 php extra php-horde-form_2.0.8-2+deb8u2.dsc 1c9627d2be1ec26a9da644f6695e183a 3372 php extra php-horde-form_2.0.8-2+deb8u2.debian.tar.xz 5a4e5fd5b209162b9c5853764ac20d7f 138720 php extra php-horde-form_2.0.8-2+deb8u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEz9ERzDttUsU/BH8iLNd4Xt2nsg8FAl6BDIIACgkQLNd4Xt2n sg97Yw//XbTmk7Ue/1DSbuZAAgsp6TbHq5IiYV+GcUHvzVOByjll1lpi6Bp+5Z8H VNMa7aycCEuf9DRNQIdbkriWrwS3ZY8DpFJUozdLGGMbj4uwpoe1y+avz0xKRbuX U0RkPfQwpJ/OyQTvhBbEP7VJfwejIkPOPaMSNoOPZ82BL6K5SYDk+CfbKdPvUN/x tfXhY+JBcKzmrKikgMLJ3IT0eEs0P4cU2IIqVKumLOxayPa6vUME5eMqTC3Za61f kYArzenqgHeUyPlqNwaihD8WUG4TYM6kgkOXVt2hOv/2ZtLOA2ihWWpipUWY2ypt chYsVAzSOTetxK32LPLMk66PJ8wzdFFTyexWzb2eToVFhjFgaGbPjS0KaVVK577E 7Wid+El8N7XSlBv4tLiyvX7/NeusfsX0PH/DtKmAVo6ybevCZ+2UqMqMvuITmFZl zIl+wpa0jFyTOblKXxOhdJcVTpymDAKgrxx4vTkFbY49CBUGhfz+PjXG0YDtt0+w Uvdz5l4ndrNA8kpNnmd/0i6HW+hxtmT/5IU+qlrjfb7uBaoszl5Icr4Dqt6rAE1J u5JCQ/UK0A93WPfGfV5gwAOUwuEUo5h/VBKUfGnU19Ktjj+IfGmfDzPlGxin4XXI PplHYmnhOI+JTALiHzE2/TPtnCjVY0/FH0bjJiwa3KekNlFVr3o= =7RqO -----END PGP SIGNATURE-----