-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 10 Apr 2020 20:32:35 -0400 Source: php-horde-trean Binary: php-horde-trean Architecture: source Version: 1.1.7-1+deb9u1 Distribution: stretch Urgency: high Maintainer: Horde Maintainers <pkg-horde-hackers@lists.alioth.debian.org> Changed-By: Roberto C. Sanchez <roberto@debian.org> Description: php-horde-trean - ${phppear:summary} Closes: 955019 Changes: php-horde-trean (1.1.7-1+deb9u1) stretch; urgency=high . * Fix CVE-2020-8865: The Horde Application Framework contained a directory traversal vulnerability resulting from insufficient input sanitization. An authenticated remote attacker could use this flaw to execute code in the context of the web server user. (Closes: #955019) Checksums-Sha1: 7b6ae903616fb9da3b06a83c1bcc2dfc98019acc 2061 php-horde-trean_1.1.7-1+deb9u1.dsc 67c047a148e6d2896ba2827a1f1e56bbebde21ce 658190 php-horde-trean_1.1.7.orig.tar.gz 6357fca29bfac7cc160aa583c3e52638aeddda0a 3760 php-horde-trean_1.1.7-1+deb9u1.debian.tar.xz 324fc4294b203dc03b9fbb14ce7c629992332f46 6240 php-horde-trean_1.1.7-1+deb9u1_amd64.buildinfo Checksums-Sha256: 29f53d62f600432a6bdb6af9cc33819724b19e091cdc6a75a55abb01aa50758d 2061 php-horde-trean_1.1.7-1+deb9u1.dsc 9c279c7c8b5f555829e140788cfdbf1f7bfe0dddeb74c0c6d723289b48b110d6 658190 php-horde-trean_1.1.7.orig.tar.gz 7a2ccf8ce3287252cedf0b8b17415e8d72b7ebd54db84fcc031b265bfa9b11b8 3760 php-horde-trean_1.1.7-1+deb9u1.debian.tar.xz a1e021e3ea2f69ab5e663b24f0c2adb7178a7e345522a11974f953c97ff3a4c6 6240 php-horde-trean_1.1.7-1+deb9u1_amd64.buildinfo Files: c4958f860492209ac2e118158b7009e7 2061 php extra php-horde-trean_1.1.7-1+deb9u1.dsc b9c45b8385f44471c81af5dba9161de0 658190 php extra php-horde-trean_1.1.7.orig.tar.gz e193d55e344d7fa1924cacf92243f909 3760 php extra php-horde-trean_1.1.7-1+deb9u1.debian.tar.xz a27ace71c0965f4386b37809e3019dfb 6240 php extra php-horde-trean_1.1.7-1+deb9u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEz9ERzDttUsU/BH8iLNd4Xt2nsg8FAl6TFJsACgkQLNd4Xt2n sg9N7g//e+Um++F2D/M3xnUMoIRzjrfQBpebQddCPgmtdEBf1qzMmKLJNyTK7mF4 AgGcuv/2ZSwxeOS1tY6YxJbCgzu6PPcHVZv7le6+aYtj5etHYCNHWifJatCjA8mB gbNW+q7EdJJIhDUyH1tGlkOiHU51mo2jqemsQaUQir3f0p45RNi/8p6GLw8Ym+KT jE6SXfYsXN5AnrbCBY8jxJuFnulV7v/LjxwfLesV9U9vHci/k4N7HewiDasm6qWY C0PCiIqL5SmhAL19efE600J01Ua/F0eOzxN9/h0PgRCAm7uF8RZqa9G06JCGy9Ye xyzC1HZVtsCPr5W3zv7ytsgy7E3G2H8eTN7WZ+FKOKkaWIacQ3jl3wy+n+Z49bVl Z61tjv+X2ON3LAuifg1LjRxy1BzIHr3cON0HgqJodeYN7d5WTqyuwrz7TyFBd4jo 79FEXHlmf2835FkSIRZxtu6fO8O2DK0IHrCXfovwn/nNeu0ViPBEXoHW2pG3La97 L3iuCFzgiJ6FymJ4FpnYMo1WSPRbGz/GTLmkOVewfcbyYAkemcF1tFNMP4krwW1d z+bDi4ALh32nmc5YiKkiEQqyZXUnlXl9ipitAumBNbHwPKjE8OdmyrpmrtLuhJz0 AS3k+p3Jzf3Cwn3+/J8aQ7OAhloVxwtC5yE6mSQ5457WFp9RVQM= =vP0J -----END PGP SIGNATURE-----