-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 27 Nov 2020 19:15:59 +0100 Source: tomb Architecture: source Version: 2.8+dfsg1-1 Distribution: unstable Urgency: medium Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org> Changed-By: Sven Geuer <debmaint@g-e-u-e-r.de> Closes: 975084 Changes: tomb (2.8+dfsg1-1) unstable; urgency=medium . * New upstream release. - Fixes CVE-2020-28638: A static string is injected as enryption key when pinentry-curses is used and $DISPLAY is non-empty. (Closes: #975084) - Adapt d/patches/* to new release. - Remove patch not required any more. - CVE-2020-28638.patch - Remove patches adopted by upstream. - fix-default-cipher.patch - fix-errors-on-open.patch - Add new patch to fix mistyped function call. - fix-typo-calling-pinentry_assuan_getpass.patch * Update d/copyright. * Update d/control. - Remove needless field Pre-Depends. - Bump Standards-Version to 4.5.1. Checksums-Sha1: 8dbea979f73ed30a0b3066299fd32ecaa029206e 2037 tomb_2.8+dfsg1-1.dsc a6126609ffca9fab5953118efa336874d7450e87 1204976 tomb_2.8+dfsg1.orig.tar.xz 26015c0654cd80f8c6004775c1623c83b2251825 6912 tomb_2.8+dfsg1-1.debian.tar.xz e3f67053101a553d03218a7b010b0865a2899814 6089 tomb_2.8+dfsg1-1_amd64.buildinfo Checksums-Sha256: acb3f64c0eb72be68b4876bc0eb7b2178673fecdc11cc204107a30d4319d3efc 2037 tomb_2.8+dfsg1-1.dsc 566403a031a68312d33949c9f19b7d1d6690dcfbc5aa0d132fb41aafa9ab4954 1204976 tomb_2.8+dfsg1.orig.tar.xz 9c4232e5e3865ff028b9d3297ae25eb4624e5029762aa271e57726bb357b3c18 6912 tomb_2.8+dfsg1-1.debian.tar.xz 009ccef150340f62ce701a1c70fb3f52eeda2841300de23d51b3420c6abb0d8f 6089 tomb_2.8+dfsg1-1_amd64.buildinfo Files: 9d247bcbb0ddd39c8c7fe8f1a22029c5 2037 utils optional tomb_2.8+dfsg1-1.dsc 7602449ca461ad601184f3ccc415b0b2 1204976 utils optional tomb_2.8+dfsg1.orig.tar.xz b511ba153532723ef13efc1691375b84 6912 utils optional tomb_2.8+dfsg1-1.debian.tar.xz 32f9ce62f33f4c4743c953ade6ed2717 6089 utils optional tomb_2.8+dfsg1-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJKBAEBCgA0FiEEPfXoqkP8n9/QhvGVrfUO2vit1YUFAl/BQyYWHGRlYm1haW50 QGctZS11LWUtci5kZQAKCRCt9Q7a+K3VhZNYD/9WUSibeBuJ4y33wo/myCKXSXKm Dwo5x9G/m0r2FjzvcUvfksj6NLQKjo3uSKIaxFzvRYQ0WJ/cSRB7UZe5Zahz/Uj4 R3rqqUCNyUkdMD9mvYtLSomiyv9KSXJTxus0MX05WgP8uWdHeosNc55OgFodMiIR 929OxIkcVD1gtGW/fvoFw76tlqo5746EY5ZkyKkhUTuQt+fy1UVOBf5NDd+GCfK9 rngAAfyDFqr9BVNIjHEyXBsnhPr2PKzv8ZyI8GG71oeDlC7X3eNA0/nupiMbZIuP CkJuawk9Ncf9hniNUWzEzZNCybxpbgT00Kem3p1imJgZJAob9CEgi4gofx4TOWFj SxSh7COZvvceUDbIpb75gddcqWRG8vk2hs+Ld4p22ovS+ZxAAbZycVMnu2rknGwr 7olvtu0MaUYRex7HewgNC3WmiaNONTTMmc9UlN24KXP07Itk5rHOKZ+QAXSwrB9r i/+mc4LSdw44ZGeASbMMsldFxZVwCfoLJNB1zZlz/KqrWk0vNZQdAlZ6zbBVnPrc vcqt2yu7PJkUPT7ouwC/KTpoDA+74W5/9tVspjM48jzI87aiS0ABTEjdbZRDotDH qSrNrzIFMno7VFqygtGblxs0UzL1gioTL8I5eqeottxKAIQczWfaZ9wnuCk1PK3k hv09CnazDenE4tp/8Q== =o+yP -----END PGP SIGNATURE-----