-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sat, 18 Dec 2010 10:54:34 +0100 Source: tor Binary: tor tor-dbg tor-geoipdb Architecture: source all amd64 Version: 0.2.1.26-6 Distribution: unstable Urgency: high Maintainer: Peter Palfrader <weasel@debian.org> Changed-By: Peter Palfrader <weasel@debian.org> Description: tor - anonymizing overlay network for TCP tor-dbg - debugging symbols for Tor tor-geoipdb - geoIP database for Tor Changes: tor (0.2.1.26-6) unstable; urgency=high . * Fix a remotely exploitable bug that could be used to crash instances of Tor remotely by overflowing on the heap. Remote-code execution hasn't been confirmed, but can't be ruled out (CVE-2010-1676). * Housekeeping: Update IP address and port of directory authority gabelmoo with data shipped in 0.2.1.28. Checksums-Sha1: a3772ca28dc5b800263d44ff41af03bb5bfa628b 1461 tor_0.2.1.26-6.dsc e6278bef734f53bd41a36ef46976e587881843a7 95442 tor_0.2.1.26-6.diff.gz ef62dfe16fc2d494cc476be3b1257a4b0f90cf44 805448 tor-geoipdb_0.2.1.26-6_all.deb 1f580a8969988c56f304317bf267f008220c58d9 1535662 tor_0.2.1.26-6_amd64.deb 63328b3230417fd9672a2888443ce01ee3f1dc45 927632 tor-dbg_0.2.1.26-6_amd64.deb Checksums-Sha256: 520d136c62aba1b19afd8d31fbd91e2a4c1c49c24423290cbd5946e73a619f96 1461 tor_0.2.1.26-6.dsc 6f8b269e1c0381c86872c78b6996d88432fe70cd5b05da4318e98b005c35d368 95442 tor_0.2.1.26-6.diff.gz 40de3307d94cc27ac5dd80a71c890097fd954c5066e85e6c743216b63dcbbbaa 805448 tor-geoipdb_0.2.1.26-6_all.deb 593e5a193902313baa5959cb853dd2db63f625e3fd93c9b5ced079f05eeffd60 1535662 tor_0.2.1.26-6_amd64.deb 7f241b6ef351ef95e6e7319a5220bd691d6d510d804afb50d3433e276c556712 927632 tor-dbg_0.2.1.26-6_amd64.deb Files: 1b1ebcae415b5fbd2f1bf858b7a9a055 1461 net optional tor_0.2.1.26-6.dsc f1e3794345a97a7d461020d867c669e5 95442 net optional tor_0.2.1.26-6.diff.gz c439ba0f0d10c77b9e9a17e911e2d87b 805448 net extra tor-geoipdb_0.2.1.26-6_all.deb 1a0b4748e646997e2ec17eaf2952f424 1535662 net optional tor_0.2.1.26-6_amd64.deb c1f819a5f6c28410e8463e3a97df0226 927632 debug extra tor-dbg_0.2.1.26-6_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJNDwzKAAoJEDTSCgbh3sV33X8IALKWh5OuOieoqLdW8bmA8ZRu Jk+/ajECmPG9ragoiYtdIZu2qV8gMXlxs2Vfu8MifGKZyAhW4nDdNk/rG0Zz6WHI /LeLcc2xDwyNmqwgCEyTkSkJHSkAcSw1dr2B3AdIwfcwLT+f6LGMFuZHYeky7iic ESTrEK9HMrn30yfpKhphhlrFnFMJ7x+V6vTyMlwG/2Xbp8zUfi0zr5xoIVeW90lt kSKvWJF2pSye+2gd0Ij0lfFLQlxj+oEd2H0pffBgcxkSTYTIqmaGHAgQ/+kK8dmo 72UYyo79a+5iZnpWKrTrRNZXprUwU/0B20JnPSN59399vobdQ+NLT0IFHe4/zyg= =T3VZ -----END PGP SIGNATURE----- Accepted: tor-dbg_0.2.1.26-6_amd64.deb to main/t/tor/tor-dbg_0.2.1.26-6_amd64.deb tor-geoipdb_0.2.1.26-6_all.deb to main/t/tor/tor-geoipdb_0.2.1.26-6_all.deb tor_0.2.1.26-6.diff.gz to main/t/tor/tor_0.2.1.26-6.diff.gz tor_0.2.1.26-6.dsc to main/t/tor/tor_0.2.1.26-6.dsc tor_0.2.1.26-6_amd64.deb to main/t/tor/tor_0.2.1.26-6_amd64.deb