-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 18 Jan 2022 18:01:05 +0000 Source: flatpak Architecture: source Version: 1.12.4-1 Distribution: unstable Urgency: medium Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org> Changed-By: Simon McVittie <smcv@debian.org> Changes: flatpak (1.12.4-1) unstable; urgency=medium . * New upstream stable release * Alter the solution to CVE-2022-21682 to avoid regressions: - Revert semantics of --nofilesystem=host to be the same as 1.12.2 - Revert semantics of --nofilesystem=home to be the same as 1.12.2 - Add --nofilesystem=host:reset which means the same thing that --nofilesystem=host did in 1.12.3 - Users of flatpak-builder should update it to 1.2.2 to resolve CVE-2022-21682 * Other bug fixes: - Clarify documentation related to CVE-2022-21682 - Improve test coverage related to CVE-2022-21682 - Restore compatibility with older appstream-glib versions, for backports * Set high urgency to resolve regressions in 1.12.3 Checksums-Sha1: c20ad4d6b4e3054325c37164724a5d2851417e30 3633 flatpak_1.12.4-1.dsc 7745ab42122080e89fef75a6dc2e7d98703c7b2c 1556548 flatpak_1.12.4.orig.tar.xz c87bc23cb3d8e8f4a5c5607a77d4a3158618bcaa 33072 flatpak_1.12.4-1.debian.tar.xz 3dcd284e6dd0aa1d670d3928e552329774ede40a 11951 flatpak_1.12.4-1_source.buildinfo Checksums-Sha256: 8c53b725fb4348ab0328862cdc86942073364eb3140bb0e97dd783f9fab2c11d 3633 flatpak_1.12.4-1.dsc 792e6265f7f6d71b2a087028472a048287bed2587e43d2eec2c31d360c16211c 1556548 flatpak_1.12.4.orig.tar.xz a4e32ddf89f6a52f8f7dd57777debdbd25ed9ee8d25af49dfad55db1d10eb56e 33072 flatpak_1.12.4-1.debian.tar.xz 176dc726e44b8c826c9a1b34d5370a5b4b83cad3dec54aecd31d212ecdddcdc2 11951 flatpak_1.12.4-1_source.buildinfo Files: 50eeffe1b7e12c64efd37006575f69d6 3633 admin optional flatpak_1.12.4-1.dsc f61d895ff59cd2bbc1046adb5450acbd 1556548 admin optional flatpak_1.12.4.orig.tar.xz ba88861558405de2bcf9a1132133df3f 33072 admin optional flatpak_1.12.4-1.debian.tar.xz 4c01c15e7462dae5af03136d08fda679 11951 admin optional flatpak_1.12.4-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEENuxaZEik9e95vv6Y4FrhR4+BTE8FAmHnD+0ACgkQ4FrhR4+B TE/hfA//aQl7IwCeYIIE51Q1HlryouVkm/FQ0XL5qfI4lc/tWRQbUUjgT8rA131C n0imjPxRzGZRYeRSMzloIDpBJFt4j0Yj8HyrhRsRfwCsb/TZ/tv3rC+38qJujFJf BkQo6Su5t6KV3ikI2xp9B/MycaAqm6ZqxXSamMRTWk4S2esly5YppURPmRp+TYHA KcP/CK98Y9xn4YAMN1zShVw7LDGCS1WWU074uqbXQJClvyuc66eNySjNEp4Vtr7p /6s6DoHznQhrDaxyM5CohZulM5glEkjaEtirZP+Xap2frc2gcYVFaXU0H+G8ueWY XGqIpaBF+K13e2/BHCHsTqeaZDiu4kaiyhHSbAw4FqUbzJLWelWSj+vtDgVVNVLr hY807PAZmOSqcqYybdEtZZGyFQ0KBWsqRiHpvv8pFMrp16IPs6SNVwRRg3kc9dkU ObwFngQ1qX3GiKd771cjbB8xxlp1Vy0WGE43i8R4xh9WjVTRUEo0rWlxcDYaM35U YyCoNTLCjl0XKrYLmJD4IDH94LXBo6VXz1/Q5tpVNq8C3A9+rTcaJI6j11w+VW3a 78xhSnnqX55RKGDa6LhG4F2iYyY96DKXrU+PNxhrhwy400873J8ZuegIrt+HSoSe FEr/sXw8IBzCAFI7P2SMNMgeNH2bePPLXSjjl8r5wnYgxQ3zOk4= =Hdz9 -----END PGP SIGNATURE-----