-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 10 Dec 2020 15:40:27 +0100 Source: apt Architecture: source Version: 2.1.13 Distribution: unstable Urgency: medium Maintainer: APT Development Team <deity@lists.debian.org> Changed-By: Julian Andres Klode <jak@debian.org> Changes: apt (2.1.13) unstable; urgency=medium . [ Debian Janitor ] * Apply multi-arch hints. + apt-doc, libapt-pkg-doc: Add Multi-Arch: foreign. . [ Jordi Mallach ] * Fix typo in Catalan translation. . [ David Kalnischkies ] * Prepare rred binary for external usage * Support reading compressed patches in rred direct call modes * Support compressed output from rred similar to apt-helper cat-file . [ Julian Andres Klode ] * gitignore: Add /build and /obj-* build dirs * gitignore: Add .*.swp files * HexDigest: Silence -Wstringop-overflow * patterns: Terminate short pattern by ~ and ! * SECURITY UPDATE: Integer overflow in parsing (LP: #1899193) - apt-pkg/contrib/arfile.cc: add extra checks. - apt-pkg/contrib/tarfile.cc: limit tar item sizes to 128 GiB - apt-pkg/deb/debfile.cc: limit control file sizes to 64 MiB - test/*: add tests. - CVE-2020-27350 * Additional hardening: - apt-pkg/contrib/tarfile.cc: Limit size of long names and links to 1 MiB * Raise APT::Cache-HashtableSize to 196613 Checksums-Sha1: ba172352be056e7ab628f52200bbcf074a7194e6 2760 apt_2.1.13.dsc edff2f4570bed8f8b0e0cbeb5bbf5e397511ed14 2182384 apt_2.1.13.tar.xz 1f1e0028ac1ed99ff43b4c18c2d0b4aed90b85f1 7455 apt_2.1.13_source.buildinfo Checksums-Sha256: 99c3a902ba25a3a3884b3ba29bad125d9376da36184c5062eb343d973cc062c4 2760 apt_2.1.13.dsc ed56790183618df99d60d4a37729a7abca7e780607ad91f5d9f2a4ee84f7c9a1 2182384 apt_2.1.13.tar.xz 1cac4f8d5e941b22527788f73231e3ba8dfd817848c598e26d4ab9d8b57a40be 7455 apt_2.1.13_source.buildinfo Files: 01feb515e4f14b32266d1607235cad17 2760 admin important apt_2.1.13.dsc b6d3bbb4bd9fd4741a21f004776304ea 2182384 admin important apt_2.1.13.tar.xz d2248e0d88d9cd60d15230e815e2f4e9 7455 admin important apt_2.1.13_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJDBAEBCgAtFiEET7WIqEwt3nmnTHeHb6RY3R2wP3EFAl/SNJgPHGpha0BkZWJp YW4ub3JnAAoJEG+kWN0dsD9xL+wQAKkGfFtPj3qhKi9I6B7gmtxg7BFeK6kj27lH B5Z3Xdl9T6h6VJNW2B679NnlAA+jOL4Fg/R8auCcv0zm7ucXbdvzCi5hOevENQf+ qVwEqmm9nXcUGq44t3mSEjgXm7NuaOau5pkO12UQos3tRNnDEqbugUgX5sOilcbN 6VZ5zS0VOQb72kpYyNfO/Cw8P23DUa3b54MzD7DbTf12gJ3zmQfCUic0jMHwPB/l /dXg0FdZbxf4zNKVvYeXYn23KKtFZp1uaEmxNftz5JmzCin5fzvdXj0PDR0oakTw wzJ+tTBZi/h+LIHIGoGHGPLr+DralQWlGwmcuajlZ0Xq84vf8KnCN/jpUM4U+koI hPLMzzv82HiruscZkeIfhlDQgy8GgxWPPdjHlIb4eOca2hz2suYm0pe8Z1z00UJQ h41s8MR2ikjkANNtSdMqUBr4/5njXfnXz4rrFkcYEnTI468RgN3tFzXw2c31rogy c3OesN6VaAagMwF0l0zX2Zai50+XKghWiccX3MmE2F6lxYs0CWBc4oNPQy1M5GCT 2R83jcJ5GKplvZPavPDe+m9DVumqiFE2ThYaiz38y31Q3lfP9XdSiwe7ZuoMEN/l 5zRieVi8J5LgAezq46/5IzdJRXDX7X7pVcyCKtYIT7RPPvkC5DYomRbg4bhyoVAO k46WFou4 =/B8+ -----END PGP SIGNATURE-----