-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 17 Dec 2008 09:27:01 +0000 Source: git-core Binary: git-core git-doc git-arch git-cvs git-svn git-email git-daemon-run git-gui gitk gitweb Architecture: all source Version: 1:1.5.6.5-2 Distribution: unstable Urgency: high Maintainer: Gerrit Pape <pape@smarden.org> Changed-By: Gerrit Pape <pape@smarden.org> Description: git-arch - fast, scalable, distributed revision control system (arch interop git-core - fast, scalable, distributed revision control system git-cvs - fast, scalable, distributed revision control system (cvs interope git-daemon-run - fast, scalable, distributed revision control system (git-daemon s git-doc - fast, scalable, distributed revision control system (documentatio git-email - fast, scalable, distributed revision control system (email add-on git-gui - fast, scalable, distributed revision control system (GUI) git-svn - fast, scalable, distributed revision control system (svn interope gitk - fast, scalable, distributed revision control system (revision tre gitweb - fast, scalable, distributed revision control system (web interfac Changes: git-core (1:1.5.6.5-2) unstable; urgency=high . * debian/diff/0005-gitweb-do-not-run-git-diff-that-is-Porcelain.diff: new; fix possible gitweb vulnerability: calling "git diff": Jakub says that legacy-style URI to view two blob differences are never generated since 1.4.3. This codepath runs "git diff" Porcelain from the gitweb, which is a no-no. It can trigger diff.external command that is specified in the configuration file of the repository being viewed. Checksums-Sha1: c32b811783dc3ea2882e10b6c59b0bde877dbd1a 1295 git-core_1.5.6.5-2.dsc 18d33ae9597bb217359b9f54f7011acd80ecff7f 225639 git-core_1.5.6.5-2.diff.gz f43508b094ea82697eb9ca62943d08be15f22f58 1076466 git-doc_1.5.6.5-2_all.deb a3a6d389df639931f25f38ebc42cc6ec9e81e4d2 230656 git-arch_1.5.6.5-2_all.deb 0c27d4d44128858c6f26c503177daae534109295 266838 git-cvs_1.5.6.5-2_all.deb 3003e8ec5525455d5541549d7407419c004833c4 267896 git-svn_1.5.6.5-2_all.deb 8b00a7e248b120ed0dee45ebdd6a8a87849d106a 217418 git-daemon-run_1.5.6.5-2_all.deb 412c1b6856d54c5bf235a8355711a7cd1a6828e5 228948 git-email_1.5.6.5-2_all.deb b1ea279c98a5d003b62bba9d7d105daa9bc67a66 401174 git-gui_1.5.6.5-2_all.deb b0274bd579a76acc54056aa504dbebfa7b897987 298258 gitk_1.5.6.5-2_all.deb 93804bbc310ad561bf3137c4cd54e685d38bde04 267666 gitweb_1.5.6.5-2_all.deb Checksums-Sha256: 04fee32a91a89015e7f153708fa20ebfa77329398875c06c5b189d4b7f199688 1295 git-core_1.5.6.5-2.dsc 75cc04b4ecfa2d498f8c76fcaab58a9bc7293cf7a05316fba26c6fac3ee943d0 225639 git-core_1.5.6.5-2.diff.gz 62a828c9714e66549430b17f52b7f950b79ca807ea896484b32005510235cb80 1076466 git-doc_1.5.6.5-2_all.deb 0c15765412e1c70429b8e3189f7e0bd40cd6c888680e4118c572ea8f794d8811 230656 git-arch_1.5.6.5-2_all.deb a473742e23ca859f51091de17ad86ce7b87af28fb18657b7bcb0baec2080ad7b 266838 git-cvs_1.5.6.5-2_all.deb 8203830a1e8dfaeada0c123acf0759dd2253125c6b1f227bae24c86aa0c9e637 267896 git-svn_1.5.6.5-2_all.deb f781d0ec398679eaa8a42cfd3730f4472cff69d7d33efed7fbc578f44c852bf7 217418 git-daemon-run_1.5.6.5-2_all.deb 2a7ea048eea80c4ee08b7f7e158652f5c96deb273fd0184e040e61770e31e9d7 228948 git-email_1.5.6.5-2_all.deb 857250a28c495f6f606f2e294185abb4adaa8fdbe45ee1228a7a06dee00b57ee 401174 git-gui_1.5.6.5-2_all.deb 589550b939bc1bff44881914cab440d9abda9ec785266f857aae501e26e682fe 298258 gitk_1.5.6.5-2_all.deb 56d29f665bb609fb240ba6ed5346974ed3f960b864d8492ea3fe5481e1cbd909 267666 gitweb_1.5.6.5-2_all.deb Files: db83db0698812a73613f60cd4e994c50 1295 devel optional git-core_1.5.6.5-2.dsc 04033473b92c0c09d7fef359e9432e3b 225639 devel optional git-core_1.5.6.5-2.diff.gz a60375da58cd36cc516b3a3edda8aad0 1076466 doc optional git-doc_1.5.6.5-2_all.deb 3a5bbf36daa77dec4520a0c356af429b 230656 devel optional git-arch_1.5.6.5-2_all.deb 6dc6829802de72633e75050dba746f69 266838 devel optional git-cvs_1.5.6.5-2_all.deb 3650684c9251a5b3786d48e1c8439f3d 267896 devel optional git-svn_1.5.6.5-2_all.deb 6e992cdf111dc7a0d3ce1da3b75c8623 217418 devel optional git-daemon-run_1.5.6.5-2_all.deb e641931ddd7ca99c195834649c8b13e7 228948 devel optional git-email_1.5.6.5-2_all.deb a24a2cc622ea1baf0b1de4e59e8b657e 401174 devel optional git-gui_1.5.6.5-2_all.deb 215a6486e2970c370b79f1563c05074f 298258 devel optional gitk_1.5.6.5-2_all.deb 51d4c05c7407510118dc18665e61e30e 267666 devel optional gitweb_1.5.6.5-2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iD8DBQFJTMzcGJoyQbxwpv8RAvmNAJ0Q3xmWZTXD/5TepvVpBABkc2+HKwCgpRXm JDFoOJV/UqeSiCsmzwqfg+4= =qMFF -----END PGP SIGNATURE----- Accepted: git-arch_1.5.6.5-2_all.deb to pool/main/g/git-core/git-arch_1.5.6.5-2_all.deb git-core_1.5.6.5-2.diff.gz to pool/main/g/git-core/git-core_1.5.6.5-2.diff.gz git-core_1.5.6.5-2.dsc to pool/main/g/git-core/git-core_1.5.6.5-2.dsc git-cvs_1.5.6.5-2_all.deb to pool/main/g/git-core/git-cvs_1.5.6.5-2_all.deb git-daemon-run_1.5.6.5-2_all.deb to pool/main/g/git-core/git-daemon-run_1.5.6.5-2_all.deb git-doc_1.5.6.5-2_all.deb to pool/main/g/git-core/git-doc_1.5.6.5-2_all.deb git-email_1.5.6.5-2_all.deb to pool/main/g/git-core/git-email_1.5.6.5-2_all.deb git-gui_1.5.6.5-2_all.deb to pool/main/g/git-core/git-gui_1.5.6.5-2_all.deb git-svn_1.5.6.5-2_all.deb to pool/main/g/git-core/git-svn_1.5.6.5-2_all.deb gitk_1.5.6.5-2_all.deb to pool/main/g/git-core/gitk_1.5.6.5-2_all.deb gitweb_1.5.6.5-2_all.deb to pool/main/g/git-core/gitweb_1.5.6.5-2_all.deb