-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 11 Jun 2020 15:17:51 +0100 Source: libphp-phpmailer Binary: libphp-phpmailer Architecture: source all Version: 5.2.9+dfsg-2+deb8u6 Distribution: jessie-security Urgency: high Maintainer: Debian PHP PEAR Maintainers <pkg-php-pear@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: libphp-phpmailer - full featured email transfer class for PHP Changes: libphp-phpmailer (5.2.9+dfsg-2+deb8u6) jessie-security; urgency=high . * CVE-2020-13625: Prevent a output escaping issue in the `Content-Type` and `Content-Disposition` headers which could have could permitted file attachments to bypass attachment filters that match filename extensions. Checksums-Sha1: ec42ecfa7627c4e6bcdbca1540de114f682b31a9 2129 libphp-phpmailer_5.2.9+dfsg-2+deb8u6.dsc 3570dabee592d1525136e0959700c85d790d3280 151878 libphp-phpmailer_5.2.9+dfsg.orig.tar.gz 82bf4a4a24e6597c628c0574fba96c6d87236d22 10024 libphp-phpmailer_5.2.9+dfsg-2+deb8u6.debian.tar.xz 0c71f93f67c3855478c762f92ec479b98658c624 132164 libphp-phpmailer_5.2.9+dfsg-2+deb8u6_all.deb Checksums-Sha256: b3089eae099fb2895f11c77a733babb6e1ada02efa33b41be82899deb3c5a1a0 2129 libphp-phpmailer_5.2.9+dfsg-2+deb8u6.dsc c1aa13b418eede3e0dab351fb6d8a9a877a536379f11e142ecd50764405260e9 151878 libphp-phpmailer_5.2.9+dfsg.orig.tar.gz cae890685fbd0c99f4d0abbd189518e7b1fe6644e164349e5ea6995e10c82362 10024 libphp-phpmailer_5.2.9+dfsg-2+deb8u6.debian.tar.xz d721adcd83198ce7317516734f360ea97bb53b1c47959497654403d0601c7e4b 132164 libphp-phpmailer_5.2.9+dfsg-2+deb8u6_all.deb Files: f359ee24171ad8ab2d0b7748e5b5bc93 2129 php optional libphp-phpmailer_5.2.9+dfsg-2+deb8u6.dsc ac2201e869561115b347ed0b2140650b 151878 php optional libphp-phpmailer_5.2.9+dfsg.orig.tar.gz afe2e0a8f3be15ebecbf80ff43df9266 10024 php optional libphp-phpmailer_5.2.9+dfsg-2+deb8u6.debian.tar.xz 4c43e0707d0c5527786a353459cea6bf 132164 php optional libphp-phpmailer_5.2.9+dfsg-2+deb8u6_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAl7iP0cACgkQHpU+J9Qx HlhQVQ//Qssnq3AW3AQG5bCqPRy/+v8xrPK+hBM2A+eDI0JqNqJYUS6gYBoBWncO Y/Jli7HHGlH2y9HoYuml9Z/EJj7kC9d+hDgcqe2xxU/tnnKt3zmLq8/bdhRBRGgc iWErNsjrU2lc1hwMrorwzzP7hylne9vrrFqv3j3aOXO9AWl87cYQ81t0wK0w+UVn WhVnJrUppcFKmkuTX7Ew5x4bMOlCEn61EL0KvLs+rd8nKvxvFH6GDO9Bz4TU975C TUQW9wy1GLDEU/1L6K2jwQJmkFN11vnGocqs6VM+sGbmw/xZfl3in5anYg3Ml1Fa M4v5nIL5aHbXWmcCW7Q421NnlOyjBAZ+T3ujb14JftesxFF0hER0YzG+n8tkoE6q jtV4a3A+dkWGPC5fKE8al2vj9YWyv4PLui7/OiBMvwwSBnknK0ZSsAy7TKvPIwLy tiCwP89snX25ifv3Q+kOLW/B3YEWVUqXIZ6yhHMBf+oTFMov/gBg0VbusEkTqYa/ BwmwHqapJ9ZAc4RMiEiPCW0riYqcFE7OZLaWvD9M4KOeVQYGzVSOFZVN1vP1R3ne 5a0yQZCJ/awqUK2bqb/E57OvupA74O3FsNxRz3VdVl2s1tdSqml5mjM6IOOWl0VA qABnER6H21LfzfYc61Tx/wvEoX8GF67edqshjRO5qH1JvBgA7A8= =plMk -----END PGP SIGNATURE-----