-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 19 Jan 2025 20:33:26 +0100 Source: tryton-server Architecture: source Version: 5.0.33-2+deb11u3 Distribution: bullseye-security Urgency: high Maintainer: Debian Tryton Maintainers <team+tryton-team@tracker.debian.org> Changed-By: Daniel Leidert <dleidert@debian.org> Changes: tryton-server (5.0.33-2+deb11u3) bullseye-security; urgency=high . * Non-maintainer upload by the Debian LTS team. * d/patches/zipbomb-fix.patch: Add patch to fix TEMP-0000000-9B1564. - Restrict decoding gzip content only from authenticated users and reject with 415 Unsupported Media Type for others to avoid a possible zipbomb vulnerability. Checksums-Sha1: 67ca65bafe6aee77fdd4f30d861c6a1d8843497d 2366 tryton-server_5.0.33-2+deb11u3.dsc ee283538629149ad07237472ca21ac1a01899d5e 659717 tryton-server_5.0.33.orig.tar.gz b82195d523fdceae159a53e855a6296544e6eb8a 33664 tryton-server_5.0.33-2+deb11u3.debian.tar.xz ebc6de0c7a665b0e76f864f39e9f711eb7346778 8632 tryton-server_5.0.33-2+deb11u3_amd64.buildinfo Checksums-Sha256: a60e2a4f54b083fa79b9f9c340cdb5bbfe6cebcfd5ff18d4e41f7143c0b9298a 2366 tryton-server_5.0.33-2+deb11u3.dsc c19a18ead60c49b7a3e3ed8fa2dacca4ead73fbd1665781377ee38a24f5a02fb 659717 tryton-server_5.0.33.orig.tar.gz e0073fa0819a433f28f234ee7b321d39fe2a3fc6b029401b191491ad04bcc90d 33664 tryton-server_5.0.33-2+deb11u3.debian.tar.xz 1631504bce5fb22cce868964559c3d4d60c6fb3e5bf7078c9dcc4f9d8c141465 8632 tryton-server_5.0.33-2+deb11u3_amd64.buildinfo Files: 78542e703ff88bca493625d231152dfe 2366 python optional tryton-server_5.0.33-2+deb11u3.dsc 24d24af6aebae9080fee3e21c9c3d13f 659717 python optional tryton-server_5.0.33.orig.tar.gz 50a4f3d2ceaaaee514fa9cb3b6631e27 33664 python optional tryton-server_5.0.33-2+deb11u3.debian.tar.xz 4b15432a64b283a48739593012d4deac 8632 python optional tryton-server_5.0.33-2+deb11u3_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmeNXxsACgkQS80FZ8KW 0F215g//efiEw4tQ+MJxLi6XchG8Ys8irYgwLQ4tEWboHIQ8PE78bevVljOMZPZO 46KnWKMR+oQ3M8Ef+De7ltd9Y42wLyW8m6zslstTGdLJTYKKA4NsXu2tmbipR4A6 O2vhHk+jhwwsulLMTxdNZvAEXp1SGSn3afC9SOv0Anzq5u/L+FcFC2vygAUVtfw/ KICxIJBlW+ATCQyP2JIQ7tZ0HtHRMgb/+TRp4hXIGUJKn+E1YJ1GQDjoq4lgbdpY HK+jeSNhsqHoejOZa3p7+MwMPumE/SG3NfsGVtvCFvlmYR67kQq2H8dpj1qZ/AZx IHHPVB2E8C+3AmwpxQNIpZLaMX/mnNgygzvnm3DZtM1v/Gyjfdx0WbgQDc+jZ8J3 rs0Ept+ntcRvJa+XuFzDXBAE7ih4RaPHLFRNjuSfWjaKMhCZAF/somQ0ryh7ax7b y/bgneESfzY+M/QUUMKTcvvKnsm+O894Hc+XZ8CJyT+RM9TaoJ6Dvtfzid00TlSx vzW1mxF8/rFPlukbooYl4iDXba0DK+kYcF9bjI0yMb7hbNO8jtluHNKGgVvVPfT5 7pd/GOUoZi8stTFfH2e3EIsjYbUCmG3QDPIMK2L2ATzxwYTLj8kyA6ZgA/NqRM9s d2Zx7zgOU8j3iQXSRiXlHwBUh8QgIkYNM0m8wjH1ahDJPL07tyE= =augh -----END PGP SIGNATURE-----