-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 31 Aug 2020 01:56:11 +0530 Source: asyncpg Binary: python3-asyncpg Architecture: source amd64 Version: 0.8.4-1+deb9u1 Distribution: stretch-security Urgency: medium Maintainer: Piotr Ożarowski <piotr@debian.org> Changed-By: Utkarsh Gupta <utkarsh@debian.org> Description: python3-asyncpg - asyncio PosgtreSQL driver Changes: asyncpg (0.8.4-1+deb9u1) stretch-security; urgency=medium . * Non-maintainer upload by the LTS team. * Add patch to fix possible uninitialized pointer access on unexpected array message data. (Fixes: CVE-2020-17446) Checksums-Sha1: 82f9e68875a981d096b378158ad99a5ca77890aa 2142 asyncpg_0.8.4-1+deb9u1.dsc c27fc3f71274680f2484bdee4cde7c810bbbf3cf 405615 asyncpg_0.8.4.orig.tar.gz d5d13fdc9207ebec3e1b94c7c8dc085ce281184f 6488 asyncpg_0.8.4-1+deb9u1.debian.tar.xz 3bd11731bd7ced9777b67317400863d09a1dcb74 8337 asyncpg_0.8.4-1+deb9u1_amd64.buildinfo 664481c3713643082f70334084c1a9c9630bbe87 750478 python3-asyncpg-dbgsym_0.8.4-1+deb9u1_amd64.deb 0982597cf833548092c413598a65eaca0ac156ab 269904 python3-asyncpg_0.8.4-1+deb9u1_amd64.deb Checksums-Sha256: b75bdf4f8c204dac243e681092e2101b009c4fec9204bd39fc71cf345ae51b1f 2142 asyncpg_0.8.4-1+deb9u1.dsc 700ecf42bb1aa057b3fb78599315983d73315b56c65382eb9c81d755c9faf1c0 405615 asyncpg_0.8.4.orig.tar.gz e6fb028ddafdfdc38e77baf19842c5d54ce673bd6dc977f5e41394760ac6f7e1 6488 asyncpg_0.8.4-1+deb9u1.debian.tar.xz ec59a0239eeabe81390ba4a194fca81fecd01f940d648097b5cfddb4dc84dc61 8337 asyncpg_0.8.4-1+deb9u1_amd64.buildinfo 0e5a6cb96dcc023aa1fcadc82e69e19d35661df27d42015e826bae9878097cf5 750478 python3-asyncpg-dbgsym_0.8.4-1+deb9u1_amd64.deb ea5086682a42c491ff54ffecc07e57c10ea3cee8f13405a8c2b464f677ada676 269904 python3-asyncpg_0.8.4-1+deb9u1_amd64.deb Files: cbe09b95dbdff659249f41df8f00d98f 2142 python optional asyncpg_0.8.4-1+deb9u1.dsc 89607e36b271e42df028b32e5edc7d8d 405615 python optional asyncpg_0.8.4.orig.tar.gz 228edcbb5b778b5d159d325c4ae8ef6a 6488 python optional asyncpg_0.8.4-1+deb9u1.debian.tar.xz e4c58efcf4c3ee58482174b873e65162 8337 python optional asyncpg_0.8.4-1+deb9u1_amd64.buildinfo 167c18bbe65c3c5c6e5bb5f30fef216c 750478 debug extra python3-asyncpg-dbgsym_0.8.4-1+deb9u1_amd64.deb a740c776757d3d4619d6033e333e37b1 269904 python optional python3-asyncpg_0.8.4-1+deb9u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQJHBAEBCAAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl9MKgUTHHV0a2Fyc2hA ZGViaWFuLm9yZwAKCRCCPpZ2BsNLll8MEACZ8tGMvFdKCd+pC9UqEILZ0CkPU6wi jYWmJ2KxQNusQkkLm4J33ZKw7M4G4Uml2nI4vJhTglJt82Cu6qMZBA+8xzLVgptP 1MFGdGJU8ndG6dvTlXg9UrnCQFzG6kUhqs11/7I3ncYb7gRurTiHwDHS4beUH2T/ Ey0n20IpcYl/8am33iwWlz8hiwU+iKR5gsQvhXfjrOgNAoA28TDaodkj5jS4IooO f++6smd5kcjvSALJUfFHMXpJglabFkPsvnAzXn72tlvBpXTZF6GwEF+rnS5e3qdO hEpuWz3JTMX+QnnuaR6IZo4MQ2fIRAQdmo9hiq/KY2GBPdc1BvoFG2IuhKwJEELK dIp5eVujXgQejSQHXsaaANoxCBkHD33cGAC3wmYwsrTzSwNUh/hODh0vq6LSlTSQ a5QD3uQQmqkanETwTr4wFJSJOdZRDoonrH1Gu2dugoTQhuJtMSPdjUay3bUfUm2j CJbFl7vZGKI9dkQ2bXfOThdtgA7gedR2+0MHQXQ1E1Wb4YwhVVf917Jtni1WmDEK i/OYcQWqrvLBhgN7VGV1FZIEW4tlNZZm4jMEQTJE5zWPiqMmsiePl4GwaO5P6Umt 1/Cq5PBV32WOrqT2sV61IBDL37xtW6pR8K/4F8UvMUxcu/w2MA6vN13Rzd6/ECjO KaU24IGzUKFOYQ== =D5uQ -----END PGP SIGNATURE-----