-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 12 Aug 2013 23:07:29 +0200 Source: nmap Binary: nmap zenmap Architecture: source amd64 Version: 6.00-0.3+deb7u1 Distribution: stable Urgency: high Maintainer: Hilko Bengen <bengen@debian.org> Changed-By: Hilko Bengen <bengen@debian.org> Description: nmap - The Network Mapper zenmap - The Network Mapper Front End Closes: 719289 Changes: nmap (6.00-0.3+deb7u1) stable; urgency=high . * Backport fix for CVE-2013-4885 (remote arbitrary file creation vulnerability) from upstream SVN repository, r31576 (Closes: #719289). The fix has been implemented by adding a filename_escape() function to the stdnse.lua standard library. The following NSE scripts have been modified to use it: . - domino-enum-users.nse - hostmap-bfk.nse - http-config-backup.nse - http-domino-enum-passwords.nse - ms-sql-dump-hashes.nse - snmp-ios-config.nse - stuxnet-detect.nse Checksums-Sha1: 719790fa3954127ceba69838ce8f58e9b9e404f2 1310 nmap_6.00-0.3+deb7u1.dsc 8911e937b2506c39bd9589c5b1b5e43a3842aebe 28031 nmap_6.00-0.3+deb7u1.diff.gz 5626fcc5946eb7e7780487845faa881afa941305 3717692 nmap_6.00-0.3+deb7u1_amd64.deb 3f247224cb7906ef228e108060fc8cad652e66b4 548604 zenmap_6.00-0.3+deb7u1_amd64.deb Checksums-Sha256: 193cc3b832df2506edd82a15783e1dae2e943eaaa411561f0b36a49056249625 1310 nmap_6.00-0.3+deb7u1.dsc 2593c56198855c183402f5ec6ce60a5fe3459c6f0bcf5bb5c266f141fc27082f 28031 nmap_6.00-0.3+deb7u1.diff.gz ddec66359fc9a9d993785a86b8d4f2f065d494cd83f638c413ef115cfd0b29d6 3717692 nmap_6.00-0.3+deb7u1_amd64.deb bb5cea0d87280cd2e4fc74b27cd40b76a0f42b4d31957ec211017259325b8cde 548604 zenmap_6.00-0.3+deb7u1_amd64.deb Files: 2ad427934e1bb97211f097217c80a1c5 1310 net extra nmap_6.00-0.3+deb7u1.dsc 8e5ec61f8a68d8d53ff8cfb2478dce7a 28031 net extra nmap_6.00-0.3+deb7u1.diff.gz e64545424da15dec9cc733f31e0eccc0 3717692 net extra nmap_6.00-0.3+deb7u1_amd64.deb 4d4d85674ada9c25cfd689473783b66b 548604 net extra zenmap_6.00-0.3+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (GNU/Linux) iEYEARECAAYFAlIJVPIACgkQUCgnLz/SlGiMAACfShTct9zw92BJKo322XZxlf9V ts4An3IRdPiwnAnqqgt5bhjFCRX/NssE =URj7 -----END PGP SIGNATURE-----