-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 04 Jan 2014 07:30:51 -0400 Source: gitolite3 Binary: gitolite3 Architecture: source all Version: 3.5.3.1-1 Distribution: unstable Urgency: medium Maintainer: Gerfried Fuchs <rhonda@debian.org> Changed-By: David Bremner <bremner@debian.org> Description: gitolite3 - SSH-based gatekeeper for git repositories (version 3) Changes: gitolite3 (3.5.3.1-1) unstable; urgency=medium . * New upstream release * This release removes world+group read permissions from ~gitolite3/repositories, and world+group read+execute permissions from ~gitolite3/repositories/{gitolite-admin,testing}. This corrects a local information leak present in (at least) version 3.5.2-1 (see CVE-2013-7203) Checksums-Sha1: f0f66538da753e18805000b39fba419c48956286 1705 gitolite3_3.5.3.1-1.dsc 06e97bdc5a0e33d166c588c05bf705d1703d0804 148132 gitolite3_3.5.3.1.orig.tar.gz 932acd56d14e1d8b104c2a8e79f01b843878b3c9 16645 gitolite3_3.5.3.1-1.diff.gz 59dc002e0b43c829ea1343c1a854e1429d2eeec8 88082 gitolite3_3.5.3.1-1_all.deb Checksums-Sha256: 7f50bb022ee3e5264ff91d084e7b6e2b60db33dfe6813b048732c44823a0697c 1705 gitolite3_3.5.3.1-1.dsc b4655d85ef60619dce76fc27222dcce483ede5875cda68b841935cd39f734ee1 148132 gitolite3_3.5.3.1.orig.tar.gz b5f10093c90fce9cbdcd5e4faedb6ffb56d5a7d43ad73d0bea1793825214bbb6 16645 gitolite3_3.5.3.1-1.diff.gz aa8ca6a1d1d22c751973159dbd6d7fc30742e161d3e2b63345169489b8be8921 88082 gitolite3_3.5.3.1-1_all.deb Files: 226867c8e7653fff442e37852388a478 1705 vcs optional gitolite3_3.5.3.1-1.dsc ccc2efa810900d61ea4868230f42bfb5 148132 vcs optional gitolite3_3.5.3.1.orig.tar.gz 1e44e783fb4521682a1ced395e748ea2 16645 vcs optional gitolite3_3.5.3.1-1.diff.gz dd70983f5a1d7aba0456baad6a7a9266 88082 vcs optional gitolite3_3.5.3.1-1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQGcBAEBCAAGBQJSx/N1AAoJEPIClx2kp54s/5QMAJCV6mt5IFumT0UeDbC7Rff7 /VvT52cYzBv3SNFQ5sfNUV3exlcjuJiJHs4zc7tjfWZbsgpNRULJwscznlXUQrYj QuttzaIpPUvGQnq+cjMXhXZbM8pJ3aT3okebtfCTzmmy8vBojrdDEmalVQW/5lQx jVMfIoOke4McqhK41DWF89JDnt89s22+WRvlHiwRIg+K1yZRO1bGNHycB1Px3AtD x/kZ1E+sPVoIQJ35+4Q3uhBBRKoxzIwy7R+em84j4O/mgDBEWK5od/p77vT6poxV 4kzVeCV0Eq3OLIX942GK/aCZge2CLxvHadwlUE4OU1ilhKJLFNGJD//ybqrmXueP 31/zsA7cApGyU/7/+1rQz5owvP7lrKnYuT7u5yz72kXbBp4yjSRRm4BTW41OToI0 5UC04cyjCS/tUY/dpTTiq9Odm2fmQzf2ZSkYg41sckeEODlKpOUGJJ/OqfcJcKNj ZlVstGtMd0dUJdhfdXwRXAGpuXDM6VE6umL9ntJhvg== =W1e1 -----END PGP SIGNATURE-----