-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 02 Aug 2014 22:22:14 +0200 Source: reportbug Binary: reportbug python-reportbug Architecture: source all Version: 6.4.4+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Reportbug Maintainers <reportbug-maint@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: python-reportbug - Python modules for interacting with bug tracking systems reportbug - reports bugs in the Debian distribution Changes: reportbug (6.4.4+deb7u1) wheezy-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2014-0479: Arbitrary code execution in compare_versions. A man-in-the-middle attacker could put shell metacharacters in the version number, causing execution of code of their choice. Thanks to Jakub Wilk <jwilk@debian.org> Checksums-Sha1: 5d950290b11a4d2875b23d3ad41367374246297e 1870 reportbug_6.4.4+deb7u1.dsc 146c6e44c015e8df0363e225ce462262d22e06b8 180214 reportbug_6.4.4+deb7u1.tar.bz2 2678b05430a111705f1216d4164a2ef68ac5c223 128224 reportbug_6.4.4+deb7u1_all.deb c77f9ec16b22b60b91ba0792fb9ad6b9227156f2 135674 python-reportbug_6.4.4+deb7u1_all.deb Checksums-Sha256: f6f637422433df4ef6a731878a00b89d7fb08a913d1c94e6f12b8a5370b2fc29 1870 reportbug_6.4.4+deb7u1.dsc 997e0726b7cdb3d4317c4bdf9362959d32409df1061e83667f5249fac88792ba 180214 reportbug_6.4.4+deb7u1.tar.bz2 26809d446e9ead25f961a5295d27dccbaba28e40b402434b8547280a68105892 128224 reportbug_6.4.4+deb7u1_all.deb 048e13e17079e39c1e2ce115366e15aa3c53c88e711857b663e8a94080934b26 135674 python-reportbug_6.4.4+deb7u1_all.deb Files: 1194dfbb986adb4176a3bde7315762f4 1870 utils standard reportbug_6.4.4+deb7u1.dsc c80e1608c50150e9cb51581474839cac 180214 utils standard reportbug_6.4.4+deb7u1.tar.bz2 609f35534eed2ba244366d937344b238 128224 utils standard reportbug_6.4.4+deb7u1_all.deb c759ecba5a33f56e9e7a895f4bcf070d 135674 python standard python-reportbug_6.4.4+deb7u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCgAGBQJT3jrAAAoJEAVMuPMTQ89ELAMP/jUD6maSYiWlGiKQ6Zy3dR9S iJY1vfRTbAscBvrK2BnFWSrYWwDE4OVimtbZJixwrqjA2CaLy/YbbITOHUt+SIKZ duPZ+jwyayzDIIqv3EqqubekHt6trkRekAwJImBE+ZQNzExImVhe3K1XYT2n/oj2 zH6GqpXZloIMzhkjdmbA+oHd9DvzpW7kMObmeAsCD+hjzdRdyB7NPHEDpCc0OaMg M4QCNVEvXjiTH7ZHEiPLEM0CHESoZJfhGzqWerjX1Nc2zWhXVNCDOfBVC8V2AEPK Tp2tE8jQNpqWqxKDBrwBhQBljQggzlEZbfLGZ78RShMWQ+sWWI5HMZtHiqXHKm67 igTHf9vjHOKXluhadD7jgeczt/2JoovXyPp9RGQtYpgk7P9LF5ASEHFDOt2Ml6/F cqxgK7Y+DVnbuJKjQWmd4U/xF5rlCqyVkP40STA1tB6b/5DBjl+4iYKvbCbnfwm3 omR1sTj7MBYFgJ/B2zcCOEWI6RtT1zrMf8rfEXkfE62VHiO7recJxyhFitGRuYBI ceh90EnuTtXtLwtA6gbjLcJXYjtfQbbtJYc2rnDMzNrenWXuhv5TOnzkq/pBJU/X yv3ah7x4ZuaokX5SljugIXsuQ+Q2MCzIpnzCwRQr6ZUsKPMVVDZcQV3S3sGfC5EI n6Tas7zPFDBExjTNob/7 =0yrD -----END PGP SIGNATURE-----