-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 03 Feb 2010 15:27:44 +0000 Source: trac-git Binary: trac-git Architecture: source all Version: 0.0.20080710-3+lenny1 Distribution: stable-security Urgency: high Maintainer: Jonny Lamb <jonny@debian.org> Changed-By: Jonny Lamb <jonny@debian.org> Description: trac-git - Git version control backend for Trac Closes: 567039 Changes: trac-git (0.0.20080710-3+lenny1) stable-security; urgency=high . * debian/patches/: + Updated 02-508019-defunct-processes.diff to what upstream actually did so that we don't introduce security holes. Upstream bug (linked to from patch) explains bug and patch more thoroughly. Thanks to Stefan Göbel for letting us know about the bug and providing a patch. This is CVE-2010-0394. (Closes: #567039) Checksums-Sha1: 2803ecf3649431f5c99f6cf520a4c034c814915c 1312 trac-git_0.0.20080710-3+lenny1.dsc 62c4055570ce817e9b74150fb5dd414f4b219d7d 28505 trac-git_0.0.20080710.orig.tar.gz ee4b9ae2921c86352defa67b89cb422126dc4804 4262 trac-git_0.0.20080710-3+lenny1.diff.gz 2f6f73f6a0d98fa275baae6c457fde3dbe3d56d2 16920 trac-git_0.0.20080710-3+lenny1_all.deb Checksums-Sha256: 5dfb8f27cffca98018b539f5cda06435bdef7a7384c21c96605ae59179f757f9 1312 trac-git_0.0.20080710-3+lenny1.dsc 58cde4328e5907af1f0684ab154a758e0ed4e9a34fa0c9c8596a18dcccc459a4 28505 trac-git_0.0.20080710.orig.tar.gz e73ffd86896ae9ae70757d125fd748df73d75b5f4a327b1bae715e21e5e18b5e 4262 trac-git_0.0.20080710-3+lenny1.diff.gz 14abe2f3ea18ab03f98e79b14274ef57c85b5e9f587b3ab2e73ee773d8c5c962 16920 trac-git_0.0.20080710-3+lenny1_all.deb Files: 4357cd66c8df3ac03273f9f858d14928 1312 python optional trac-git_0.0.20080710-3+lenny1.dsc c8220478c501b7ab3e6df97cea6d2e26 28505 python optional trac-git_0.0.20080710.orig.tar.gz af5bbdd092dfe8d953bcb2183c1228c4 4262 python optional trac-git_0.0.20080710-3+lenny1.diff.gz d91bf3dc4b15e1c999f7dc5e65e0de65 16920 python optional trac-git_0.0.20080710-3+lenny1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAktpllMACgkQwYr7ny4DlAJsbQCdGwrCGmR6t0tzs2tIfHeM2+/+ 0B8AoLEy7r/6EDdOKZbZEKfDuLIe3wrZ =yOHj -----END PGP SIGNATURE----- Accepted: trac-git_0.0.20080710-3+lenny1.diff.gz to main/t/trac-git/trac-git_0.0.20080710-3+lenny1.diff.gz trac-git_0.0.20080710-3+lenny1.dsc to main/t/trac-git/trac-git_0.0.20080710-3+lenny1.dsc trac-git_0.0.20080710-3+lenny1_all.deb to main/t/trac-git/trac-git_0.0.20080710-3+lenny1_all.deb