-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 03 Aug 2014 16:03:15 +0200 Source: reportbug Binary: reportbug python-reportbug Architecture: source all Version: 6.5.0+nmu1 Distribution: unstable Urgency: high Maintainer: Reportbug Maintainers <reportbug-maint@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: python-reportbug - Python modules for interacting with bug tracking systems reportbug - reports bugs in the Debian distribution Changes: reportbug (6.5.0+nmu1) unstable; urgency=high . * Non-maintainer upload. * CVE-2014-0479: Arbitrary code execution in compare_versions. A man-in-the-middle attacker could put shell metacharacters in the version number, causing execution of code of their choice. Thanks to Jakub Wilk <jwilk@debian.org> Checksums-Sha1: ea06fbfcb9ec3f091f04eaf77d3bf0cc206f6323 1887 reportbug_6.5.0+nmu1.dsc 175021b4a1a58990a2207491d29a189ffa9b894e 181306 reportbug_6.5.0+nmu1.tar.bz2 cac0609b515b15e5d37b0b4d65cbd0e37e5e82f0 122104 reportbug_6.5.0+nmu1_all.deb 2571821a03e78da3cac4afb46036500863692e93 125114 python-reportbug_6.5.0+nmu1_all.deb Checksums-Sha256: ad7bafe953ce1b2793e29ef798d3736611317d0b1e4f3e20084407a65fc15a81 1887 reportbug_6.5.0+nmu1.dsc 7c3049ce3cc3b24fd2b485e910c555ca609bcfb8d383809f4f4cc72056c5d5a4 181306 reportbug_6.5.0+nmu1.tar.bz2 70dccc2f0512aa4f4fd650daf34e5c12cd661a83f94f78ece005ddd72929c9c4 122104 reportbug_6.5.0+nmu1_all.deb c76eff27b13f96d37047dafcebf300f7ae6fa35236e9a811a36652a26c70f996 125114 python-reportbug_6.5.0+nmu1_all.deb Files: 5f3bd47308c9be6c782526c922da71e2 122104 utils standard reportbug_6.5.0+nmu1_all.deb 137150c257e42acf6b38969ef0bbc8b7 125114 python standard python-reportbug_6.5.0+nmu1_all.deb a693bb4b5dfc78f948d0f112df01bd1e 1887 utils standard reportbug_6.5.0+nmu1.dsc 5a7edab2374c868c09348117703d87c8 181306 utils standard reportbug_6.5.0+nmu1.tar.bz2 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCgAGBQJT3kGRAAoJEAVMuPMTQ89ELXcP/1PleewhaIAb5xKjoEVNaxYN jvbk8BEeMzsuVMvpUhThmW/Ufk6ALtTxf49/fxZ+/yVBe2qOwPNhoarbjHObINB5 WpJK5A4l/TXmpUU4PnaZPKHosa1SwgfaT8vSrTzrRrCdMyqfcNEdEWhB5IY4hWYq 7R+CGfHYHGbspYV1qjvzLw7noi78zTpX87sZaNkhRfc8a+zDP/yafRhb4Nu8XqS9 f+zeXev1ckErX5kRYyH4zYjBjmAuQVf0MAH/8oWBt14t+lZfot9mmCXOUn7lFaal /1xGEnJS8/KWV8o5Le6pjVtG+wo/RU+yz3REkAGP7lcl2jKZWqZ7eWrt9BNSUQyM 8ILkgXWEta21RCpYvXTB7OiO4DEixATTP1qIXjHhNf6MJh/EVOnSmLRB2i99qABT a265GMb9VhZxWWo6CBo6M9i9rCaHu7xQ0OEvnEske/RMw6ccRGNR0zUkQy6DST7p MBbvhROZg6X2pMOUjodh+uE0w6Ur+eigQu81MkjtSwzepr3rCGyOthIyiT/1vJ6o U8XDaRcduhWhX1kH71LtAcxpcJp2VCC3+HMiQdg7EuonYNxmPsTyxlKoGmrInQAv Eery9WXgYOJgzs2VhE3q3XXKIWIhf1IU9nGj9M6greCdTPLNFr9JXUN75LusaoZ1 ABoa9QXIBxpZmFhtj1Nu =Qbi/ -----END PGP SIGNATURE-----