-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 06 Jan 2011 21:04:33 +0100 Source: dpkg Binary: libdpkg-dev dpkg dpkg-dev libdpkg-perl dselect Architecture: source i386 all Version: 1.15.8.8 Distribution: unstable Urgency: low Maintainer: Dpkg Developers <debian-dpkg@lists.debian.org> Changed-By: Raphaël Hertzog <hertzog@debian.org> Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end libdpkg-dev - Debian package management static library libdpkg-perl - Dpkg perl modules Changes: dpkg (1.15.8.8) unstable; urgency=low . [ Guillem Jover ] * Truncate the output part file on “dpkg-split -s”. Regression introduced with the C rewrite. . [ Updated man page translations ] * Two typos fixed in French (Christian Perrier, thanks to Julien Valroff). . [ Raphaël Hertzog ] * Fix multiple security issues with dpkg-source (CVE-2010-1679): - Enhance checks to catch maliciously crafted patches which could modify files outside of the unpacked source package. - Do not consider a top-level symlink like a directory when extracting a tarball. - Exclude .pc while extracting the upstream tarball in 3.0 (quilt) as patch blindly writes in that directory during unpack (and would follow any existing symlink). Checksums-Sha1: 75fdc8a850f052cbe6b11e1238a1dbff86cfbaa2 1537 dpkg_1.15.8.8.dsc eb15f16714dfab4bdacc092261088f9fc13cc6d7 5266200 dpkg_1.15.8.8.tar.bz2 1dc76a7085f15c6451c4b9a046d0e424d7913953 418634 libdpkg-dev_1.15.8.8_i386.deb 36581dd35de543235b37d483eac4fd57630a5453 2332308 dpkg_1.15.8.8_i386.deb 4632d5e3280638971d89669d84692126f142800b 892430 dselect_1.15.8.8_i386.deb dbbd1a5dc7ca8c62a6c853d0c095431e6a4e47d6 806590 dpkg-dev_1.15.8.8_all.deb 9df9a08b5ee3e4883bfdf00f95017b07d6e8ef4e 690400 libdpkg-perl_1.15.8.8_all.deb Checksums-Sha256: 1992add475e1e8d88e07382844b68048e68e002114fcfaee4bcde26fa344b777 1537 dpkg_1.15.8.8.dsc cc9f699abf95848c4e5e3c236e7bef5af01afec63fd1fb9fc88a01af6a98f3c5 5266200 dpkg_1.15.8.8.tar.bz2 8b2918507e608a06699921846aba2cfe536fc1feb94da2da85918a90849eec8f 418634 libdpkg-dev_1.15.8.8_i386.deb 29673d3e03fe76df97fab9cc170328878790f519be5e133a6f6906e3e489e750 2332308 dpkg_1.15.8.8_i386.deb 672c7a74a808a37fbbd466656b6c8ec6af806a721dde5ed6320567b99abd073f 892430 dselect_1.15.8.8_i386.deb 070a6bf627b5730063bc17636504161964aeeeab679e5c25b5265dd0d3efeb0e 806590 dpkg-dev_1.15.8.8_all.deb b1c1856cf17a435de147c99c7394b585901ed618138e746d8a484b6989a7bee4 690400 libdpkg-perl_1.15.8.8_all.deb Files: 854e90050352c10ad6d624eae04dd05c 1537 admin required dpkg_1.15.8.8.dsc 39600c01d03c997bc12898ff85424377 5266200 admin required dpkg_1.15.8.8.tar.bz2 2adb43bdee595643896d1f067fbf0acd 418634 libdevel optional libdpkg-dev_1.15.8.8_i386.deb 78e05cc69538472eeee29621fdf4cd0a 2332308 admin required dpkg_1.15.8.8_i386.deb b0aec6815c554b52fb462052eb593327 892430 admin optional dselect_1.15.8.8_i386.deb 28ddf4e07afe847991ee2e8f763b1fcf 806590 utils optional dpkg-dev_1.15.8.8_all.deb 14812b8dd1014818b4386a86091b5cb6 690400 perl optional libdpkg-perl_1.15.8.8_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) Comment: Signed by Raphael Hertzog iQEcBAEBCAAGBQJNJiwZAAoJEAOIHavrwpq5NFIIALhCAfW2sEjo6Iy3ti2U9o4V kWo4We5va8mS0TUK2yJLpa13Z97EhEz/3G+23yOlXzkk43V0tMCHMcaAOAaFG4ET amq8bFO6BrBQpBbMbRUijQ4WMX+yuKrJglV0QrRo/Ya0+IsDPpTaEvcvu60t+jNN irLU1kovW8mkgEnbBcLwFpJX/jwMOUK6qZ8WAuaN8ehkWSfglIDKZSRA3gM3x/F8 DqLQnn+EV5zv7X+QmeUTpcDYPxsAQUSdm4E5X9+xpieHMA4ZTi1RdhZwnChQhbr2 htu/47tsRN2RZieUTwy/yOglkfU8b5DebSZHj8gRKnstLpVzsAqwKR13+WYtwoY= =8NCh -----END PGP SIGNATURE----- Accepted: dpkg-dev_1.15.8.8_all.deb to main/d/dpkg/dpkg-dev_1.15.8.8_all.deb dpkg_1.15.8.8.dsc to main/d/dpkg/dpkg_1.15.8.8.dsc dpkg_1.15.8.8.tar.bz2 to main/d/dpkg/dpkg_1.15.8.8.tar.bz2 dpkg_1.15.8.8_i386.deb to main/d/dpkg/dpkg_1.15.8.8_i386.deb dselect_1.15.8.8_i386.deb to main/d/dpkg/dselect_1.15.8.8_i386.deb libdpkg-dev_1.15.8.8_i386.deb to main/d/dpkg/libdpkg-dev_1.15.8.8_i386.deb libdpkg-perl_1.15.8.8_all.deb to main/d/dpkg/libdpkg-perl_1.15.8.8_all.deb