-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 03 Oct 2008 17:58:26 +0200 Source: libpam-mount Binary: libpam-mount Architecture: source amd64 Version: 0.44-1+lenny1 Distribution: testing-security Urgency: high Maintainer: Bastian Kleineidam <calvin@debian.org> Changed-By: Nico Golde <nion@debian.org> Description: libpam-mount - PAM module that can mount volumes for a user session Closes: 499841 Changes: libpam-mount (0.44-1+lenny1) testing-security; urgency=high . * Non-maintainer upload by the Security Team. * Add security checks including mountpoint and source ownership verification before mounting user-defined volumes to prevent access restriction bypasses (07_CVE-2008-3970.dpatch; Closes: #499841). Checksums-Sha1: aef22d9080013679c40225db16c6b4e642f0f98a 1249 libpam-mount_0.44-1+lenny1.dsc 01a86631c1a5885e9a45b88081d70f31a2161408 429353 libpam-mount_0.44.orig.tar.gz ca2497d292950d43faef9a21b99ab2cb1d115139 25386 libpam-mount_0.44-1+lenny1.diff.gz 974038ae4d97bf8d047dee5c7cfaaaf0952c5e70 104370 libpam-mount_0.44-1+lenny1_amd64.deb Checksums-Sha256: 2048629ad34b714689624e0f596e225781069c4efd0264f2e5eabebc1fef0264 1249 libpam-mount_0.44-1+lenny1.dsc f3e09e06ff3ee7eb7b6d000a74403597658ee8c96339be6537a14d2cb502b87b 429353 libpam-mount_0.44.orig.tar.gz 5fd2e5854d606cf107ebfae4d72c571c4287dff17567d7ddda87f7bb469c8c67 25386 libpam-mount_0.44-1+lenny1.diff.gz ea848594d23c17a3b6a1cbc2f1d5d62f84b3b174e80e93f43a1f966f8fe38658 104370 libpam-mount_0.44-1+lenny1_amd64.deb Files: 1db662e022028990fb1708e6bd28915a 1249 admin extra libpam-mount_0.44-1+lenny1.dsc 05ceba2445efa851deecb570f73e8e92 429353 admin extra libpam-mount_0.44.orig.tar.gz 91eb158c7447a01e838ea96dc27314d6 25386 admin extra libpam-mount_0.44-1+lenny1.diff.gz eaf2ab48e7803b09fb6f72c6044ae618 104370 admin extra libpam-mount_0.44-1+lenny1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkjmRooACgkQHYflSXNkfP89eACdEcEJaLKRYFP1uxzrQx8o/BzT czEAn3lJcm7sg2nR/dUR9lIajDeVZH7U =JVsY -----END PGP SIGNATURE----- Accepted: libpam-mount_0.44-1+lenny1.diff.gz to pool/main/libp/libpam-mount/libpam-mount_0.44-1+lenny1.diff.gz libpam-mount_0.44-1+lenny1.dsc to pool/main/libp/libpam-mount/libpam-mount_0.44-1+lenny1.dsc libpam-mount_0.44-1+lenny1_amd64.deb to pool/main/libp/libpam-mount/libpam-mount_0.44-1+lenny1_amd64.deb