-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 06 Feb 2009 19:24:06 +0100 Source: gnumeric Binary: gnumeric gnumeric-common gnumeric-doc gnumeric-plugins-extra Architecture: source all amd64 Version: 1.8.3-5+lenny1 Distribution: testing-security Urgency: high Maintainer: J.H.M. Dassen (Ray) <jdassen@debian.org> Changed-By: Nico Golde <nion@debian.org> Description: gnumeric - spreadsheet application for GNOME - main program gnumeric-common - spreadsheet application for GNOME - common files gnumeric-doc - spreadsheet application for GNOME - documentation gnumeric-plugins-extra - spreadsheet application for GNOME - additional plugins Closes: 513418 Changes: gnumeric (1.8.3-5+lenny1) testing-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix insecure search path vulnerability due to how python handles sys.path by sanitizing sys.path after calling PySys_SetArgv (CVE-2009-0318; Closes: #513418). Checksums-Sha1: da78885acfc2254c27703874602af81c808d2452 1846 gnumeric_1.8.3-5+lenny1.dsc 5084285100a675ec05778b3dff21c2921d23ba0a 18444243 gnumeric_1.8.3.orig.tar.gz c289430f9fe3f527270d34e70287ba610a7e4d0a 133428 gnumeric_1.8.3-5+lenny1.diff.gz 4917d729fa1730da8d61e0863693b89114f08cf6 5266518 gnumeric-common_1.8.3-5+lenny1_all.deb 9204a23e36ac52920255b946ef750777d941a79b 4092756 gnumeric-doc_1.8.3-5+lenny1_all.deb ea1393452745b8b6f3c545e99274e309aae5a727 2438276 gnumeric_1.8.3-5+lenny1_amd64.deb 1859dfc8f9a2f19b31e98048cfc8e25052391944 160012 gnumeric-plugins-extra_1.8.3-5+lenny1_amd64.deb Checksums-Sha256: 661c7520903d959e6fec9b34390f870ebf6c2ec7176c6eb9d51058cbc9e9788d 1846 gnumeric_1.8.3-5+lenny1.dsc 6cfda7ec35db90172f5b5770cc4cd58fd18f5b21021f5149a61b333c05606b8c 18444243 gnumeric_1.8.3.orig.tar.gz ef61a71eec2bb55e5b50f75cf248ef422774b1c8bdbb50001dff4041af7ea2fa 133428 gnumeric_1.8.3-5+lenny1.diff.gz 210ba2a879cf1542db603fdc3f42536a770f630378c14f11ec6d72525ced3f28 5266518 gnumeric-common_1.8.3-5+lenny1_all.deb cd77628cf3b65fc480db00b968a8c79ca45f2a250ebec61151de87fd0f2412e6 4092756 gnumeric-doc_1.8.3-5+lenny1_all.deb 0cfa78c75add89e650630785ed09e72fca7387c2f209e8d9ec2260e19f68da06 2438276 gnumeric_1.8.3-5+lenny1_amd64.deb 9f2ff299a4f5c38e5d552c6768f7f716da18847e43a5452ddc4f1b4eb992c835 160012 gnumeric-plugins-extra_1.8.3-5+lenny1_amd64.deb Files: 377cf6b431c0004d8ef4f4cc4fbec364 1846 math optional gnumeric_1.8.3-5+lenny1.dsc 64721d3c0d48ffeb5bf721315682cdcd 18444243 math optional gnumeric_1.8.3.orig.tar.gz f19ea8628fa54879b6217ccf081ac73e 133428 math optional gnumeric_1.8.3-5+lenny1.diff.gz 70efdf09d1b3887cdbb1a140902dcacc 5266518 math optional gnumeric-common_1.8.3-5+lenny1_all.deb 415e25e05c0a74ce65a506bcfa7ebaf0 4092756 doc optional gnumeric-doc_1.8.3-5+lenny1_all.deb 016a07bcad84334cc9bf6ff898b81173 2438276 math optional gnumeric_1.8.3-5+lenny1_amd64.deb 1c6def4edbac607542173b272d3aeae4 160012 math optional gnumeric-plugins-extra_1.8.3-5+lenny1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkmMlRsACgkQHYflSXNkfP9QiACbBsnd5im03RdikIHD9RomrDzW +44AoKMqlAbRvkeR53ub4yLuYRWVBtM8 =st77 -----END PGP SIGNATURE----- Accepted: gnumeric-common_1.8.3-5+lenny1_all.deb to pool/main/g/gnumeric/gnumeric-common_1.8.3-5+lenny1_all.deb gnumeric-doc_1.8.3-5+lenny1_all.deb to pool/main/g/gnumeric/gnumeric-doc_1.8.3-5+lenny1_all.deb gnumeric-plugins-extra_1.8.3-5+lenny1_amd64.deb to pool/main/g/gnumeric/gnumeric-plugins-extra_1.8.3-5+lenny1_amd64.deb gnumeric_1.8.3-5+lenny1.diff.gz to pool/main/g/gnumeric/gnumeric_1.8.3-5+lenny1.diff.gz gnumeric_1.8.3-5+lenny1.dsc to pool/main/g/gnumeric/gnumeric_1.8.3-5+lenny1.dsc gnumeric_1.8.3-5+lenny1_amd64.deb to pool/main/g/gnumeric/gnumeric_1.8.3-5+lenny1_amd64.deb