-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 03 Sep 2013 19:33:20 +0200 Source: libmodule-metadata-perl Binary: libmodule-metadata-perl Architecture: source all Version: 1.000009-1+deb7u1 Distribution: wheezy Urgency: low Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: libmodule-metadata-perl - Perl module to gather package and POD information from perl modul Changes: libmodule-metadata-perl (1.000009-1+deb7u1) wheezy; urgency=low . * Add CVE-2013-1437-documentation-fix.patch patch. Addresses CVE-2013-1437 as (serious) documentation bug: Module::Metadata executes code when gathering metadata about a module by design. In versions previous to 1.000015 the documentation stated, however, that Module::Metadata provides a standard way to gather metadata about a .pm file without executing unsafe code. * Rewrite short and long description. Rewrite short description matching the X is a Perl module [...] scheme. Rewrite the long description based on the Module::Metadata POD, containing also the note about how the information is gathered. Checksums-Sha1: 736b87899fe70e527f0a60723c5f1ae185bd5bcd 2255 libmodule-metadata-perl_1.000009-1+deb7u1.dsc 71b7cec7fccc547ad9574e560dc927b24a8e44b5 2640 libmodule-metadata-perl_1.000009-1+deb7u1.debian.tar.gz bf7e5115428a291c126ff51f04d303b0475d3dde 18128 libmodule-metadata-perl_1.000009-1+deb7u1_all.deb Checksums-Sha256: 6f4e74b0466871793aecb5a04ccb20049360a98b2b0c88c3fee814221f2feb9e 2255 libmodule-metadata-perl_1.000009-1+deb7u1.dsc fa67ca0ac006dd2fa666a64d4c0f9d745d1460b263c1f649238f404bfb0ef7ea 2640 libmodule-metadata-perl_1.000009-1+deb7u1.debian.tar.gz 0d7c1d6aad6f41ef28a21709282784f665f62669c43c4ec4d59a89aa43a2d5fa 18128 libmodule-metadata-perl_1.000009-1+deb7u1_all.deb Files: 6c21fea959b2b2e8bb7a107812d3a5a1 2255 perl optional libmodule-metadata-perl_1.000009-1+deb7u1.dsc 99fb67de905987c216bb3ef50728e699 2640 perl optional libmodule-metadata-perl_1.000009-1+deb7u1.debian.tar.gz eeccffa8eff76388ab581ac0b377e1cf 18128 perl optional libmodule-metadata-perl_1.000009-1+deb7u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (GNU/Linux) iQIcBAEBCgAGBQJSJi2IAAoJEHidbwV/2GP+I14QAMx55gS29ss6Pk8vhxVoqM2n /VdhtCewjcR2s4LA3+foeEEwjk597TYVdwny6kGyTxN9wYg6VBSsAyoDRFP5t4jR nOb6mTJyxVOal9lecn7Nq6R4Ac9GoLjLQIbWNJ8SSteTikHp5cj9ZKASQREr/45m UDXYKqki9hLV2fH7vfx2ZWClZh5yIbBDwBCkbMMXd77pNVfwOlrnOckBYi8HpXJj D1vpbuEdwWLvCZKPw8jYZZJBhHjQy6SiIljZg4WoF5uzqllT4yc1U1mepbdmEYrC 7vSmaUzVpbVZT3R2rqr++LamXHQSvTr4S21p54uQ3MLNe1YjJM9wShhypoPk1AkN oEc/MEhaKb9A7wt0wmWa2h27hie8roEw/0gXtdHw7OwnCE6GYkoOzvD/C5eIVGvt F6qg04IsF0t03hsd1NQ+Z8RdD3j7F2c47pySDsNJCuYiss0GqvqYnuJ+8pLCybBw af3xUcoQ13zeJx1Z1WPU9u0V+g+9i3M+IkMJFlKz5FF57GbI3uu0szd4C/sgI92T osLs8LgaMhfs8ZN0uZLihWn1fy1q+lXbca7V8hnBcfGSwDEnrmoU6REOECi49fjd SgYVGCbwbx8oCKxqKT+C+kNbX3/4y75mbj2vj9dSch/MXsi1BBbARix+9VTqXexm k38UKDwlxNcE0cmBHC3j =KKgC -----END PGP SIGNATURE-----