-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 20 Oct 2021 21:03:02 +0200 Source: squashfs-tools Binary: squashfs-tools squashfs-tools-dbg Architecture: source amd64 Version: 1:4.3-3+deb9u3 Distribution: stretch-security Urgency: high Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: squashfs-tools - Tool to create and append to squashfs filesystems squashfs-tools-dbg - Tool to create and append to squashfs filesystems (debug) Changes: squashfs-tools (1:4.3-3+deb9u3) stretch-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2021-41072 unsquashfs unvalidated filepaths allow writing outside of destination via a link Checksums-Sha1: e386fa34cec4ea670aa539222e4a561ef24eddc8 2205 squashfs-tools_4.3-3+deb9u3.dsc a615979db9cee82e4a934a1455577f597d290b41 182550 squashfs-tools_4.3.orig.tar.gz d83b78b04556b874aa48f6ba84767c652000612b 20912 squashfs-tools_4.3-3+deb9u3.debian.tar.xz 6f84b7cfca6bbb94c86697cbc2fce6e7a4b444ab 322192 squashfs-tools-dbg_4.3-3+deb9u3_amd64.deb c2396a5105c7334a6e8b884feb67452fd53dd658 6537 squashfs-tools_4.3-3+deb9u3_amd64.buildinfo 869900ae3dd3c6274eab1aff22040be966d92a51 124032 squashfs-tools_4.3-3+deb9u3_amd64.deb Checksums-Sha256: 0b0ff11346495ea81669406e7113c9f016e2af7ef0c1b16afc0bb739beaff9a9 2205 squashfs-tools_4.3-3+deb9u3.dsc 0d605512437b1eb800b4736791559295ee5f60177e102e4d4ccd0ee241a5f3f6 182550 squashfs-tools_4.3.orig.tar.gz 1a5bf594d3db8f8a2c19cedfeb03aa5966776f2612be440b1b1aa456aae5f54d 20912 squashfs-tools_4.3-3+deb9u3.debian.tar.xz b43cc44b529e17b7a82d578ff6101918d5db729932fb9097b2314266570b6c3d 322192 squashfs-tools-dbg_4.3-3+deb9u3_amd64.deb 3eb63241c61b8d41a42d4a2ceaaa0a021f048f187fb541b6e666e6998ceaabba 6537 squashfs-tools_4.3-3+deb9u3_amd64.buildinfo e8c2562946c4f79cb7b7e4e88475e1a683ee3f20dad01a9befa86403a0559a6a 124032 squashfs-tools_4.3-3+deb9u3_amd64.deb Files: ad01323c404146e1733a668dec6f83b9 2205 kernel optional squashfs-tools_4.3-3+deb9u3.dsc d92ab59aabf5173f2a59089531e30dbf 182550 kernel optional squashfs-tools_4.3.orig.tar.gz 5888b135918c8d943617e94ebc22ea04 20912 kernel optional squashfs-tools_4.3-3+deb9u3.debian.tar.xz d0f2e1784df391d4b2e5ea395566da75 322192 debug extra squashfs-tools-dbg_4.3-3+deb9u3_amd64.deb 49f36279c05e1db4284387cfd50480a0 6537 kernel optional squashfs-tools_4.3-3+deb9u3_amd64.buildinfo 68aaa54941afbc40601ad825edd7bd7f 124032 kernel optional squashfs-tools_4.3-3+deb9u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmFwiatfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR+aiD/0c2H34IT1H91HUjK4ay+ElUvmGeg0k WZVrms9+xYiLeN6CBgPma/ug2zj+/fNhLJ46wX+YvGldHQXmIFVBhc2PIvK41EDU eBakbOqwxcQrveBnQjK3lmWWwjJLhoYaWnfM6hTOC1FznSaQ8OJJEyzZsqZh6UbX XXxYSO4MyKruPwMqkhKEdc3E2wd5pk2j2U+1DLhkEP/eSLZgiV4UWK8J6mzYpF/M PvauRiOuz4SUxaCCVLxeqfLqrqM/1tSqkn/O+x19tP8wN1ooVZO1KOuT+ZRAgPCr yGRePZHOHUoUHIJh4t49BhBxfqbRJCLfS2KwC3QqtnQd66R2LhxGnOqONLJ6bxtY B7O7n+DttvXfRlfgQQCOeD42aiZ6BiOFhuuhzzpLE5gAv6MnEPxwI9eyuObz6/b0 80fBKa2eJXn6V8pXDzp09q1pcRZup8Nsxqs1vwL12wbgZeHpBxVHQaV9mboG21mu 4IVaFyV4hJjvHcRzdmp/tQiBXBdu9zAUVXGvkioO+ZaDLdEBB/NHyA0ZKTXQtZNV 0fnY5D+7KK+ECR3xUJORhicdr1piTBGtsySDS24bnZq4zYus3/g1g/WDBWGDp/C0 8sNL2jXD/4IAbP64OCzIFc+81+Rp7XZslMEM6VIChSMqFSyq2OGu+Z8N31540rvK UL3sXKU3vNYy2w== =WLFp -----END PGP SIGNATURE-----