-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 15 Jul 2013 11:23:44 +0200 Source: chicken Binary: chicken-bin libchicken6 libchicken-dev Architecture: source amd64 Version: 4.8.0.3-1 Distribution: unstable Urgency: high Maintainer: Davide Puricelli (evo) <evo@debian.org> Changed-By: Davide Puricelli (evo) <evo@debian.org> Description: chicken-bin - Practical and portable Scheme system - compiler libchicken-dev - Practical and portable Scheme system - development libchicken6 - Practical and portable Scheme system - runtime Changes: chicken (4.8.0.3-1) unstable; urgency=high . * New upstream version, including upstream fixes for: - CVE-2012-6122 Use POSIX() poll on systems where available. - CVE-2012-6123 Added checks for embedded '\0' characters. - CVE-2012-6124 On 64-bit machines the "random" procedure no longer truncates result values. - CVE-2012-6125 Improved hash table collision resistance. * Added fix-untrusted-code.patch to prevent execution of untrusted code, see CVE-2013-1874, patch provided by upstream. * Added fix-command-injection.patch to fix a command injection vulnerability, see CVE-2013-2024, patch provided by upstream. Checksums-Sha1: 74bc3e82911ed1a136b37c00afa404b75dc4373b 1210 chicken_4.8.0.3-1.dsc 0f356e3a7eb2805656efd16bb40576d25510817d 2463380 chicken_4.8.0.3.orig.tar.xz 3b6c2f70087a2bc06b7824677c36804ccf78098d 7669 chicken_4.8.0.3-1.debian.tar.gz ae14402dc055aeca05756bdf6691d1ccdf19db13 1451606 chicken-bin_4.8.0.3-1_amd64.deb a2ada707427f9d058fc6ccd30ed580bc019998f1 1334504 libchicken6_4.8.0.3-1_amd64.deb 0ba0cd4b0de6969dfa64773f2694e1c017670c97 1666022 libchicken-dev_4.8.0.3-1_amd64.deb Checksums-Sha256: f467f70a8bae5757b820d7222170894dd4221a2c14afc1116f21dce0ea1a41c5 1210 chicken_4.8.0.3-1.dsc 49c97e9571f35e01e1604470e1877b6617652e580cf3373b96bb6d10ff8abbc6 2463380 chicken_4.8.0.3.orig.tar.xz 8b9562abc83700c873db987ba52e9211df1241b47f595834a7d5732586c235b4 7669 chicken_4.8.0.3-1.debian.tar.gz 39a550d82379f3557042c9302f47fe59a7c9be781b852ce1ae3078f1db701818 1451606 chicken-bin_4.8.0.3-1_amd64.deb 01c7403b167db006cfcf3eb8629263b3fe7b7571de6be51078a1fb4b837d2510 1334504 libchicken6_4.8.0.3-1_amd64.deb eece53d7d0abd89631ba07b88204180df599045b4dadf62e3a551f7d145e57b6 1666022 libchicken-dev_4.8.0.3-1_amd64.deb Files: b0d70717e9a7ae1f51e2794d0dddd662 1210 interpreters optional chicken_4.8.0.3-1.dsc 3929a75f76e1bb00a0f7a62a36150e4f 2463380 interpreters optional chicken_4.8.0.3.orig.tar.xz 1c9c1116471285f22082e71e0e014596 7669 interpreters optional chicken_4.8.0.3-1.debian.tar.gz b200a0c35ef9089c9654766a531811cb 1451606 lisp optional chicken-bin_4.8.0.3-1_amd64.deb 8f830467189ae73526c980bed03ca4e2 1334504 libs optional libchicken6_4.8.0.3-1_amd64.deb 440773ae1a6d8508cad8b0aad376ef45 1666022 libdevel optional libchicken-dev_4.8.0.3-1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlHkIPkACgkQNHp9kxdgFe2zdACgjxUsKpN3x9cDBq3IVAEsWMKz 1RwAoJYfS0500EIPXj1dmUgU6i5G8BIk =KxnQ -----END PGP SIGNATURE-----