-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 14 May 2020 16:49:11 +0200 Binary: apt-doc libapt-pkg-doc Source: apt Architecture: all source Version: 1.0.9.8.6 Distribution: jessie-security Urgency: high Maintainer: APT Development Team <deity@lists.debian.org> Changed-By: Julian Andres Klode <jak@debian.org> Description: apt-doc - documentation for APT libapt-pkg-doc - documentation for APT development Changes: apt (1.0.9.8.6) jessie-security; urgency=high . * SECURITY UPDATE: Out of bounds read in ar, tar implementations (LP: #1878177) - apt-pkg/contrib/arfile.cc: Fix out-of-bounds read in member name - apt-pkg/contrib/arfile.cc: Fix out-of-bounds read on unterminated member names in error path - apt-pkg/contrib/extracttar.cc: Fix out-of-bounds read on unterminated member names in error path - CVE-2020-3810 Checksums-Sha1: a268e5954897c5f3b5e31c81c0aaa07960c8788f 301264 apt-doc_1.0.9.8.6_all.deb f7db8359b78a3cde0d1b26461a54b68e515d5569 749338 libapt-pkg-doc_1.0.9.8.6_all.deb 837611698f08d580ec82d397d6a8b9f836d3c6ab 2396 apt_1.0.9.8.6.dsc 8cd009cad3d41e0e9bc4454e5fd335219003fa6f 1784448 apt_1.0.9.8.6.tar.xz Checksums-Sha256: 53cf1c4f68d93da2dd18f1a064c571add04e4aac41ac791ad0288481a6031e4b 301264 apt-doc_1.0.9.8.6_all.deb c4ba58032485c34a3c01b96d2afc254b383df8fcf47e2a1176f5fde377fb3a90 749338 libapt-pkg-doc_1.0.9.8.6_all.deb 252f09e9a52a1470e1d38a98d313a7fe5e1737c775946f3348d0e10251d3ccfd 2396 apt_1.0.9.8.6.dsc b1a430b0d2b54008f1cdc2b58e48a94bcc259f5b0c95cfa5450f00f5aa14e283 1784448 apt_1.0.9.8.6.tar.xz Files: b54ac6e04f16ff8bf04c459c55477412 301264 doc optional apt-doc_1.0.9.8.6_all.deb 2f046da708897df34495c52786c930ea 749338 doc optional libapt-pkg-doc_1.0.9.8.6_all.deb b38035b3744a7bc6723cdda7f06c6388 2396 admin important apt_1.0.9.8.6.dsc 23a63fa0da30ba393ad73e35097b9d1a 1784448 admin important apt_1.0.9.8.6.tar.xz -----BEGIN PGP SIGNATURE----- iQJDBAEBCgAtFiEET7WIqEwt3nmnTHeHb6RY3R2wP3EFAl69cbgPHGpha0BkZWJp YW4ub3JnAAoJEG+kWN0dsD9xg38P/0V+pFENKuFOwz6VoITT+0jie5hwtFOXcTo7 0VsAZd1dxifrJJJ0qfoU2L/jOhWQ6r009qmdI7an49dVwRzLTXlTYsYeat2Bypqt 22I53oatV0HvqFRBJL1VAiwgyzijEv8FqDnY25vFq2P+zV7nVY5KHKwUyJ1NEXo1 IEzhzV10OyTm+o9IfCgsMYsYBwVrBtE/wsAgN4NLqVbKFn5q9rNnjvy2Qri5Vsz0 qzc9xU9iGttDwc3Tn1tKiggeVUcwMaF3qDwvLh+Qd4F2+z8RbBwJwKTZC+5kV2Q8 W4jXRYlF6IbdY8u04rA9/veTgYaHA3JRiq3gBU+HRQ2IB9PwmiKhS7WWV8/tqIHk 8B7kZe5+cIUTQG7eOg3COs+yGCfYsPSNT4l8/61klfXbFfcYCfaQrCCuOio3p9AV A+tIbrYDg1fPgBb8PMzuKt6jkBWVseis/ybsZDI/VNddCbWaJNCl1GLvY6bFWsU9 +3cB2xXd77OuMeuC3Mhq+OhttmVSRPLHMg4gwmNK14pFIZM4xpTsUtzW1lnh3d+J SeGlpitVSytHNYDfhYYu9mNVnJkmJuXhRBtpBm+ZV2dTeLcciJhKg/ozeS0Z7PtI dI7bkuT3+jf+hGKaHEAkOfAQfYFsKzRfsFUtCRTYtt9pGHCF7yD33xDWp1O10L31 KnRUjLAG =a2HO -----END PGP SIGNATURE-----