-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 23 Sep 2014 12:28:55 +0200 Source: tryton-server Binary: tryton-server Architecture: source all Version: 2.2.4-1+deb7u1 Distribution: stable-security Urgency: high Maintainer: Debian Tryton Maintainers <maintainers@debian.tryton.org> Changed-By: Mathias Behrle <mathiasb@m9s.biz> Description: tryton-server - Tryton Application Platform (Server) Changes: tryton-server (2.2.4-1+deb7u1) stable-security; urgency=high . * Adding patch 03-fix-safe_eval for CVE-2014-6633. This patch introduces a fix to not allow double underscores in safe_eval and uses literal_eval whereever possible. S.a https://bugs.tryton.org/issue4155 Checksums-Sha1: 021c6b9a884fc00589e8eb8fd0216130901817fe 1767 tryton-server_2.2.4-1+deb7u1.dsc 218ce50b2255ec4886a6925f06283e7342be5e59 283376 tryton-server_2.2.4.orig.tar.xz e245fabc285a5a8b593c418494115e683d2c7d95 17088 tryton-server_2.2.4-1+deb7u1.debian.tar.xz 7267dee582343bea52b2f8ddada210b951afee4d 272712 tryton-server_2.2.4-1+deb7u1_all.deb Checksums-Sha256: 0cec0af82c3aca157a8ebaf53486ef7d624da911d7a853cfb37ba15e173049de 1767 tryton-server_2.2.4-1+deb7u1.dsc 74d3db176788d054f06aaabf9d30f4fa8772329ac6d93bf046515040cf2c0251 283376 tryton-server_2.2.4.orig.tar.xz fe9390a1ce1b4358e94d760051142427513dad144e4028705ba51c0ca6a96c62 17088 tryton-server_2.2.4-1+deb7u1.debian.tar.xz d4d67a04592494f8879b61953345fde4c896264a918816534d1c8c7e70256027 272712 tryton-server_2.2.4-1+deb7u1_all.deb Files: 2817fcb336f9d121ac0f32543c42cb0f 1767 python optional tryton-server_2.2.4-1+deb7u1.dsc 690903b5f0b4c6706ca18ddb36e2f69d 283376 python optional tryton-server_2.2.4.orig.tar.xz b0723d66b570a389f57998a101c164f9 17088 python optional tryton-server_2.2.4-1+deb7u1.debian.tar.xz 48b3f8fb936e897a3ed22e900e0d689a 272712 python optional tryton-server_2.2.4-1+deb7u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.19 (GNU/Linux) Comment: Signed by Raphael Hertzog iQEcBAEBCAAGBQJUIskaAAoJEAOIHavrwpq5aRIH/itz1mYMduB519U2A3PQaSAi jmtSKaSdTRf2pIfpjTDW/taXL9/zTGeP3affpS4gYT0Uyt40rgldi/ZX/7hXTgcD sy5ol3lTvsAbfkWxgmUS69FsnpzEw5+EC8XyDGBRIZb6II2CNV0kK8D3+SiuZ6Wh UnLV+GkdsGt8Oa03jP+vu8/aRmdwzvmXGEwXYRG2MIOmJRxv3ogHc7/YoJLreTkL EONyYNTfc/ieg05GgKgCYcGQRoqWlAfT+HHzxaa4/puF6jsZfsjezC+Am+l+xJcE gmSU3gxdfLqjqySXSLhvpksst+5DCfonZM/vsQFxcXrYJ2SzER/urbQN5sy4Zic= =qqbx -----END PGP SIGNATURE-----