-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 06 Aug 2020 18:05:53 +0200 Source: firejail Architecture: source Version: 0.9.58.2-2+deb10u1 Distribution: buster-security Urgency: high Maintainer: Reiner Herrmann <reiner@reiner-h.de> Changed-By: Reiner Herrmann <reiner@reiner-h.de> Changes: firejail (0.9.58.2-2+deb10u1) buster-security; urgency=high . * Import security fixes for CVE-2020-17367 and CVE-2020-17368: - don't interpret output arguments after end-of-options tag - don't pass command line through shell when redirecting output Checksums-Sha1: e096a049c50815dccb68bf2d8fd4586251f6db61 2676 firejail_0.9.58.2-2+deb10u1.dsc 37cfbdfa610802055a194ad2ba5df6336195a77c 338120 firejail_0.9.58.2.orig.tar.xz a70d53695775902ffe4c5de8106e52fb9271346e 488 firejail_0.9.58.2.orig.tar.xz.asc 6797b03b57558e7d37b83275f1ea5a70b805111b 14756 firejail_0.9.58.2-2+deb10u1.debian.tar.xz Checksums-Sha256: 0f9083989ab2d6ad0fe577070155c976b874d5dd4eb0fdc5cbee73f8b9548a88 2676 firejail_0.9.58.2-2+deb10u1.dsc 5d2227dcc5407d801762455912a85fd65a3c79559606858be025bff0ca026432 338120 firejail_0.9.58.2.orig.tar.xz 5477cf183200f26ac4d7def38fa8b433999f18f09843618342e574d78eb73a5d 488 firejail_0.9.58.2.orig.tar.xz.asc 4e6c57d0cc5a4a925c3f7ec0ea30a9f801ed65bab120804035147cac106af2e2 14756 firejail_0.9.58.2-2+deb10u1.debian.tar.xz Files: 48ecc02128eeeec57eef3f2526a1fda5 2676 utils optional firejail_0.9.58.2-2+deb10u1.dsc a5d1e12c58430f23c553429fa77611b7 338120 utils optional firejail_0.9.58.2.orig.tar.xz d597c7d90d3e6aff60b577b88f5fc4c4 488 utils optional firejail_0.9.58.2.orig.tar.xz.asc c0423ab962ad8b019ce04e57c3fa0020 14756 utils optional firejail_0.9.58.2-2+deb10u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl8sVqpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89Ed6UQAJAhNk13TRUH3wWy4Z6V+mfjPFnYWi1l 8hgSTYZoGMokIqJNroK8Iy9R1s9FRLxvE3RaaeGOH1VunSSbR42s9T+BJXaU4D2U /cTnNrrlT0ZebYCIbWEbkcRh+135Omddw6rHWULpr2HcdRNssD+t+RAMy1AgaZ5Z gsi02K989fh0CyRPkEjneqIlogwkPgx1cl1/N2Erlho7aiFOQHrE+fjdxnjDTBvT maspCVUX1AqcN/dRxhmJgHRTcGJrkuOUwdjmVQW1bkfkj1eiFX3iY1PAu3X04Jpb Mumf//WgUKynjqivZfkvfuuSiKBgnW4ZTzzZGnF+deSjLt/gHnNbSJLGSVPdsfmJ NrWg7+xKBc2iOAyaWh7Rghkl7ckOvtQGOGFR36dr+uQr5EeBj64zp/ZxZnKzvMg8 kHz/YkM3FRJf7Vlu4NE2pTDTO99cpAe2cXDncFWYx6klWI48bCe9O6pMmtVUno4d 3fZK2CANbuTZIDcEZgta+3SSrc0Iz54Ty34FaZglvtqB0QxwmnhmQw2mCOli+kAD Sp2HGj2uU6edsHhEnbB1rJ1bcjUdexf/5UHJ2Jr1ofxhbK382YfyFsLzeJA3xNEM KPtSbUzHzjKdL6SuoPy0EKYjm2zReCA2Z7RD565g6zpZvSyHIzYwj+JJcJD0HEMr y62ndy3ssBs8 =kPVj -----END PGP SIGNATURE-----