-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 17 Mar 2026 11:33:23 +0300 Source: erlang Architecture: source Version: 1:27.3.4.9+dfsg-1 Distribution: unstable Urgency: medium Maintainer: Debian Erlang Packagers <pkg-erlang-devel@lists.alioth.debian.org> Changed-By: Sergei Golovan <sgolovan@debian.org> Closes: 1130912 Changes: erlang (1:27.3.4.9+dfsg-1) unstable; urgency=medium . * New upstream release (closes: #1130912). * Fix CVE-2026-23941: Inconsistent interpretation of HTTP Contents-Length header by inets httpd module. * Fix CVE-2026-23942: Improper limitation of a pathname to a restricted directory by ssh_sftpd module. * Fix CVE-2026-23943: Improper handling of highly compressed Data (compression bomb) by ssh_transport modules. Checksums-Sha1: d4dbbab0c1d49cd1bd33d046ba1ff5aa99e2aa68 4910 erlang_27.3.4.9+dfsg-1.dsc d4d298740bfc01cf7ccddf34afc9cd52f2d844f6 47622820 erlang_27.3.4.9+dfsg.orig.tar.xz 5a89f1784bcdcf68c44f7faeb802fabfc5d376a6 58064 erlang_27.3.4.9+dfsg-1.debian.tar.xz fff4d3996a0fd9e0973500d0bc3c27ac0bdec2d8 31200 erlang_27.3.4.9+dfsg-1_amd64.buildinfo Checksums-Sha256: b9c3d88ee1e8f3db098fbab52498907cd4014802ec88efb7798d7751223ea9c4 4910 erlang_27.3.4.9+dfsg-1.dsc b59ee725f0088a4ef5536a783c153f17c8719025815209402ba355b969d57189 47622820 erlang_27.3.4.9+dfsg.orig.tar.xz f49d5b744d678da868fe06a67826925a16f42d3114b9eb5e5756ad94deb57475 58064 erlang_27.3.4.9+dfsg-1.debian.tar.xz 7bfff2a84ca2e43183c5e9636e07a6248df50e879b517fb6c7a4fe9f68daf372 31200 erlang_27.3.4.9+dfsg-1_amd64.buildinfo Files: a4c5d9d52b4a1528ad09821bce6a0da6 4910 interpreters optional erlang_27.3.4.9+dfsg-1.dsc 77a31804f31bd02cb517708846945f25 47622820 interpreters optional erlang_27.3.4.9+dfsg.orig.tar.xz a57957a0d7f86aabdabae0cc6f32bec5 58064 interpreters optional erlang_27.3.4.9+dfsg-1.debian.tar.xz 9cbbe20dd5341083f1c6752148bc0e0b 31200 interpreters optional erlang_27.3.4.9+dfsg-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmm5FHcACgkQTyrk60tj 54dWXg/9HoiUfgSdehVn26uJm7QVqtnjF8FJiGYREOHVuZT4rnvn5+KEqTbSmEa1 kfaL8l6i3uaGGXhSxYqVELX9EOa26WaUuPBe82quP+ATdSBNiydaB8dEOZ39AHWc BaHBS66cTtwvEs7Q9HtVu4pjpMuDry0feBB/EQJBDcV6r7XtMO/l6GfdL5cY2sjS Ci6Bj3LWMYHaGR3xEjjWc8apuBiitUDfhz6bYDiOI43Gui4nY486IkbkztAW8BhY 4XqRI/WbsKGHoDM82yYwjaYmfOyYWJNJWXXpB4rJ1TcEhSANwTYtj8b/GQzw9heE 2HtMCgkjgpsW+mGvDH/LWEYv+H62J9UOUU6ZyQFcjDZXZNW4gTzNuTe1xrqSNZ0A 73eJi0IoD72ThVKHBOYZ40rWyUBuEcbc/oxzYYEVFsQxzhMkYP7RT9jpty/fNMjv GWGgwNw4ap8SQWXGOzw0ToI5OfNB7bE2iITzxAO35YeuWgRIel7V9OglqyAR4208 7JFaxNFBCoQEtOmR2ROXZV774j1njshRBvD8nbR3i6mdPRIC+J2txeqs5DXj2j55 n6JLLMefD71EQdY4z2r4pbff5Gu1ALjL4RrtvQyaPG+yu9TYHI+RnRo0jVZzbUMF pOj67mBe0/0Cl4kAb6LmRIQ79zV2uSwndeu7RSjwk6gY0LfMu6M= =R4w0 -----END PGP SIGNATURE-----