-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 06 Aug 2020 14:10:26 +0200 Source: gupnp Architecture: source Version: 1.0.1-1+deb9u1 Distribution: stretch-security Urgency: medium Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Emilio Pozuelo Monfort <pochu@debian.org> Changes: gupnp (1.0.1-1+deb9u1) stretch-security; urgency=medium . * CVE-2020-12695: CallStranger prevention. + Require GSSDP 1.0.1-1+deb9u1 for the needed API. * Fix a UAF in the CVE-2020-12695 changes. Checksums-Sha1: 9fca5f780ebda6317f8c4545cdd2bf463ce3c865 2457 gupnp_1.0.1-1+deb9u1.dsc 014b184affa8d2820467e9a344c076ad13490315 421920 gupnp_1.0.1.orig.tar.xz 3ee82c7e710636694885002f0981ac1b97a2bcae 12144 gupnp_1.0.1-1+deb9u1.debian.tar.xz 940602e43ba4de7e98e40583b30e8e76b81c631e 9755 gupnp_1.0.1-1+deb9u1_source.buildinfo Checksums-Sha256: 9a49423fdba4ee5b10ec038734e01bf8f29729aaf3abe2220070f415f6387fe9 2457 gupnp_1.0.1-1+deb9u1.dsc 934584cc1b361bf251a5ac271ffb1995a3c6426ce44cb64f9c6d779f2af9a6d9 421920 gupnp_1.0.1.orig.tar.xz 50ecf90337064760fa5a4dcb601a543af74471b61fb69ac8669b44130a987aff 12144 gupnp_1.0.1-1+deb9u1.debian.tar.xz 26ded320479db8e914e5c06c5cd878f6bba6917528323ca9f936fb80f4d3af85 9755 gupnp_1.0.1-1+deb9u1_source.buildinfo Files: 460cfbc6a6983b2071574590f2eb3393 2457 libs optional gupnp_1.0.1-1+deb9u1.dsc 09c2d0ac6dac7bd6a59bc7d7c0eb7d13 421920 libs optional gupnp_1.0.1.orig.tar.xz 75fe6ffb9c4f854f1ed59d9ffae4fe07 12144 libs optional gupnp_1.0.1-1+deb9u1.debian.tar.xz 1633d5911ddc1b4378cfa33123d554f1 9755 libs optional gupnp_1.0.1-1+deb9u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl8sLBwACgkQnUbEiOQ2 gwJMexAAgg3HsJYrgcW4mKWS6r9dZ0Cv9dRQ6Y421s3t/B1fc0er7VXBTT7K46m6 CB9uWV6x4QMCDCSFAwlcCJ2jFj5Pgl5cK3yozfcOk0AGakIiQWo72dMIQiTB/1qz 7tpf9jB6Pne4pdhmgnNjl5EmFNRUTh7b7EpNqyJjJt/T3rr7JvpWJNCsEhACy4xm fFsXP1W7NRX/j41NR2suSEZ0MjvxfQrSTzzFZCJLfDbt8rltp3CHnQX8fYakg+6t hzDkb3GTgrGDxfD4Dv/ycTmv2od1FItcj7apQDId5jHkrkTbaEDnm3+v8cxfA+Kw WQUomfdrvWDsqyIHf75Cx7UHQnydFNk3SgduXihGxccumg2cEOrp+cpRMNY7UTg4 ugbdKueSxV7vAbiuHR+Tyki+5IS3GPYvPnR9asgvP+uf2Xda8pcv5B6swjq4axn6 hqo7iKV1DWqVzxrGAwevkvS9Rztjh8EMwGSCEndnAfT3ApeMwbGjIFES9HYJKxLB YEg0Wk+d9zyvUrPfV7YK7s0U0t5FjA5ijA1UNHGDplZItsr+x2U5P0KVWyyJ5+5B xmE353R8+XNYEP7UV2+Zcn5isqvqu9d9PNYOMfLwZBzxEAHNrSIJ9jxlhh1Li4gF /X2fyrTHxCXuu3ia5KpkBgu9YRjKGg2RZSZM+PdmGMl32QSkP8k= =27tc -----END PGP SIGNATURE-----