-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 27 Apr 2020 13:02:28 +0200 Source: gosa Architecture: source Version: 2.7.4+reloaded3-8+deb10u2 Distribution: buster Urgency: medium Maintainer: Debian Edu Packaging Team <debian-edu-pkg-team@lists.alioth.debian.org> Changed-By: Mike Gabriel <sunweaver@debian.org> Changes: gosa (2.7.4+reloaded3-8+deb10u2) buster; urgency=medium . * debian/patches: + Add 1047_CVE-2019-14466-{1,2}_replace_unserialize_with_json_encode+json_ decode.patch: Replace (un)serialize with json_encode/json_decode to mitigate PHP object injection. Checksums-Sha1: e06b9a3f43fcdfd947c3e6a64188a2684cd5245c 14361 gosa_2.7.4+reloaded3-8+deb10u2.dsc a18e47d953a6459672b37741ebcb49eb6a907aa1 98468 gosa_2.7.4+reloaded3-8+deb10u2.debian.tar.xz dd68444648e04c69b5830424ea42b0067e43919a 7315 gosa_2.7.4+reloaded3-8+deb10u2_source.buildinfo Checksums-Sha256: 1604cef91469077ec42a220c46d6acda72055719d00ff5cddba64e96a1538b3c 14361 gosa_2.7.4+reloaded3-8+deb10u2.dsc 94f98c90d7fb281e6c4661359d9d0131c3394a3d91f0bd7d3fbc4794ae073174 98468 gosa_2.7.4+reloaded3-8+deb10u2.debian.tar.xz 4bc53632602d0a44e9489e7e356c8f6188ba94f07d1e8e401456cd5d3928dd3a 7315 gosa_2.7.4+reloaded3-8+deb10u2_source.buildinfo Files: 4d0fa8e41ca86eb4becaa5ea3384f6f9 14361 web optional gosa_2.7.4+reloaded3-8+deb10u2.dsc 5313f9e371e4414c51a099b0edaa5048 98468 web optional gosa_2.7.4+reloaded3-8+deb10u2.debian.tar.xz b8562d5e8e3efecdc0daec6f8530d6fe 7315 web optional gosa_2.7.4+reloaded3-8+deb10u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJJBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAl6mu+kVHHN1bndlYXZl ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxuicP/2DNfMt2Vjn0tpt4EXVZ7HnL3j7n VD1534y4fgElqHuOzmKDAKqveIg7vZZdi4r4UAA/n39ajKB5QoL2uwopyvSl9Tdu SPWk9QVCpFm62DjDuHAHNLBNfyR6XTZ26083ZlndflQMTmzHIGAXsfJpo/5Gmsxg 9Ya1gEb5+cpRkxYhOF2vH1G7uHpukhJPiBx1iyjdai0Cdzj5pyDSPgU3rwKtFeqj M0n8VvsXMMnTo/S6iO4X3O/Gy5yNW7V2zs2+znNoeIVU5so3mL2gTEdRAjzWCHZ5 vnTlo6o4Tb0yiTVgAh2U849nW/gFBIt3xmDOpFsvHP5oSp/6u1J2i369mw+uaRMV DJqVr5zOYAP/CU22dmWypDU9KWfZ2AxsZqat/CoQ1MXeyn2sHNc7g1Yzgesu+KNP 9arDyhKZu8B0F9u9BM65nqQ4Kwv8LlVj07Qv3uIHSKK8PJTWEXPULfx3lx+AYnMX U+DnIfLRjrf0/2SIlaMU2n+ip6zXsriQqooc+M7H1TtLJ7u6c7xTkM27bH2bzFi6 xXFkRW6fNReJZJiPL0KxwVeb8gpajBj2dpTK9K4izIE2xB3G4XvkOE+FXZg0lMH3 NDNBn/dW11SJkX6MbYkquIPzxkCR+UwiwDp4moh1Sjif7EmcpL+tSiTQiQ3pgkH0 uaq6ZG67rACTRLWC =RK7W -----END PGP SIGNATURE-----