-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 25 Aug 2014 17:21:09 -0700 Source: s3ql Binary: s3ql s3ql-dbg Architecture: source amd64 Version: 2.10.1+dfsg-4 Distribution: unstable Urgency: high Maintainer: Nikolaus Rath <Nikolaus@rath.org> Changed-By: Nikolaus Rath <Nikolaus@rath.org> Description: s3ql - Full-featured file system for online data storage s3ql-dbg - Full-featured file system for online data storage (debugging symb Changes: s3ql (2.10.1+dfsg-4) unstable; urgency=high . * SECURITY UPDATE for CVE-2014-0485. . A remote code execution vulnerability was fixed. . An attacker with control over the communication with the storage backend or the ability to manipulate the data stored in the backend was able to trigger execution of arbitrary code by mount.s3ql, fsck.s3ql, mkfs.s3ql, s3qladm and s3ql_verify. Both encrypted and unencrypted file systems were vulnerable. . * Upload sponsored by Petter Reinholdtsen. Checksums-Sha1: bd3b82d4abfb6157bb0913c953e42a10ad11b036 1772 s3ql_2.10.1+dfsg-4.dsc 8f835000fbce2d1f00e08723c7921f51bac2ccf9 13876 s3ql_2.10.1+dfsg-4.debian.tar.xz 518ebba8f5b5bb1582ce5ce86f911e254fd12497 529328 s3ql_2.10.1+dfsg-4_amd64.deb 5dd5058e41e9aef22e602e969202970bee2fcbfa 246704 s3ql-dbg_2.10.1+dfsg-4_amd64.deb Checksums-Sha256: f4771aa23e8d32d0921ea7895e4bd6e96221ab0ae08d8ad98262737e52352005 1772 s3ql_2.10.1+dfsg-4.dsc 6974984fbfd644406aac2169959895ca3425a7a0a29fa8fa118160a529621988 13876 s3ql_2.10.1+dfsg-4.debian.tar.xz 43060e26031e89f3be287e24604070c19b753958317fa9ce72f9b6f1f4d564da 529328 s3ql_2.10.1+dfsg-4_amd64.deb b60b70862545ac0c8192652d1e20e11c9a693462c4a8f0f730554d9ea9d1b8f3 246704 s3ql-dbg_2.10.1+dfsg-4_amd64.deb Files: 57eed192185324049be8c26f02065efb 529328 misc optional s3ql_2.10.1+dfsg-4_amd64.deb 4dbd1c4ce63a76c0eee9760c6a649f4a 246704 debug extra s3ql-dbg_2.10.1+dfsg-4_amd64.deb 2ba926894999c24cccaad33a91040931 1772 misc optional s3ql_2.10.1+dfsg-4.dsc 74d9827b7a2c5c7e5069ffae6f235585 13876 misc optional s3ql_2.10.1+dfsg-4.debian.tar.xz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iD8DBQFT/sSs20zMSyow1ykRAviaAKCjNrWbQsRuChsiOskXYY4aBeKf8ACgsKWd YqV5uqWRBLzrjSxTy9GoPNc= =K94C -----END PGP SIGNATURE-----