-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 20 Jun 2023 15:40:20 +0200 Source: python-mechanize Architecture: source Version: 1:0.2.5-3+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian/Ubuntu Zope Team <pkg-zope-developers@lists.alioth.debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Changes: python-mechanize (1:0.2.5-3+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * Fix CVE-2021-32837: ReDoS (Regular Expression Denial of Service) when parsing a malformed auth header. * Tests: Backport upstream commits to use twisted.web (twisted.web2 has been discontinued) and fix pull parser tests. This fixes DEP-8 tests for buster. Checksums-Sha1: a52276372591f216e4aeb016a2a943aa0b81832f 2409 python-mechanize_0.2.5-3+deb10u1.dsc 9d2fb74fc762e54848c0b3ed4b6a9c73722ef619 383918 python-mechanize_0.2.5.orig.tar.gz 1a3b396b2ce39a3bae30ac2a22cd1fa39efc88b1 16616 python-mechanize_0.2.5-3+deb10u1.debian.tar.xz d62009a6568aaed7867981d7414071af78c9f118 6547 python-mechanize_0.2.5-3+deb10u1_amd64.buildinfo Checksums-Sha256: 6be7df13879f926b562be7c4ccbc4cf0d93eda71c6455372c978c1c47ddeb0c7 2409 python-mechanize_0.2.5-3+deb10u1.dsc 2e67b20d107b30c00ad814891a095048c35d9d8cb9541801cebe85684cc84766 383918 python-mechanize_0.2.5.orig.tar.gz 6d96cb557d726b54321aa08fbdd74a9e9328c6c99d88487f5bbe34b438d3f37d 16616 python-mechanize_0.2.5-3+deb10u1.debian.tar.xz 960281d411467e1f62634d081dcc8524eacd11c3e2464331c68130aebf9883a0 6547 python-mechanize_0.2.5-3+deb10u1_amd64.buildinfo Files: cfd6dfa600b30c17070202f13ab8841c 2409 python extra python-mechanize_0.2.5-3+deb10u1.dsc 32657f139fc2fb75bcf193b63b8c60b2 383918 python extra python-mechanize_0.2.5.orig.tar.gz 7f04b22332bb1ccb23633499d521c0b1 16616 python extra python-mechanize_0.2.5-3+deb10u1.debian.tar.xz 9c1bdf4369ea5f4525f40f7bf44e947b 6547 python extra python-mechanize_0.2.5-3+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmSRrOgACgkQ05pJnDwh pVKeqw//W47Plh/ySVMHc9JO01Tq2gBzkCotsZtjXlwO+OLerr70GDBBUzl7Q8J4 RtaNHc8+rJwBqFnXmq/9hZXXLP8tKRsCsMmVg9F0BL/3GO9H+VxbS1Tlq1wVb53S ngfoC79I21h0WK4FnqjguAbAA1nmJ9DZ1puP8qGseaoGw4+7f/lkhFRvlkLgbbcD iW5jctbAdiQRAdaILp1+QmkNvOtsPDQoZukQEuTXnbaGDvVCsm6y4oq2E7G2kaTp CuIkVFm8husrnxBvxuJamT8pGGWiAkoudLxCNMmrl75TjDUck2mHIedF7igCSEbX EcSZ/4xmNDpcnYiIZpqYvjA16nWu2N/I5dcNXHx0TpNZo4vnRkkASPP6C/EwcsWe g+9FFqrbuVnSXuwpdneyLyYmtYMbk1E2q3KYcCQybvCTE5eG9XFxlmCTrshTHQoB UtDZeAmovpDauB0ndqGiXhQXyZLoUUzcfvAZQ5epq2So7oqnj8pmINOiykchI+WV NL2JwJdUAObchN1xHJB/ippNPA4YmZaPrraIh404e9VrplyQXlp4KZVS2PB9DnBQ XL8BCWQyofownhmd1CJRCeP/OkSN6Iel4YtIJVXcS5fsmvXn3xOSasl+wHEhk9Pq MRvSJ0p3x0OiszYWrKuPfMWlEqfawZsTZwRJpzEFeewnyYE1Az8= =PTZU -----END PGP SIGNATURE-----