-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 03 Sep 2014 22:15:06 -0400 Source: mumble Binary: mumble mumble-server mumble-dbg Architecture: source amd64 Version: 1.2.3-349-g315b5f5-2.2+deb7u2 Distribution: wheezy Urgency: medium Maintainer: Ron Lee <ron@debian.org> Changed-By: Christopher Knadle <Chris.Knadle@coredump.us> Description: mumble - Low latency VoIP client mumble-dbg - Low latency VoIP client (debugging symbols) mumble-server - Low latency VoIP server Closes: 681715 688444 742091 748189 Changes: mumble (1.2.3-349-g315b5f5-2.2+deb7u2) wheezy; urgency=medium . * debian/control: - remove obsolete Vcs entries. Closes: #681715 * debian/patches: - Add two security fixes. Closes: #748189 Mumble-SA-2014-005.patch CVE-2014-3755 http://mumble.info/security/Mumble-SA-2014-005.txt SVG images with local file references could trigger client DoS Mumble-SA-2014-006.patch CVE-2014-3756 http://mumble.info/security/Mumble-SA-2014-006.txt The Mumble client did not properly HTML-escape some external strings before using them in a rich-text (HTML) context. Thanks to Mikkel Krautz <mikkel@krautz.dk> for reporting the bug, and Gregor Herrmann <gregoa@debian.org> for updating the patches for Wheezy. - Add 35-fix-UDP-socket-initialization.diff. Closes: #742091 Fix UDP communication failing until connected user's mic is activated and data sent. Thanks to Mikkel Krautz <mikkel@krautz.dk> for finding the issue and fixing upstream. - Add 37-fix-connect-dialog-hang-dee463ef.diff. Closes: #688444 Fix crashing when connecting to a server. Thanks to Valentin Lorentz <progval@progval.net> for reporting the bug. Checksums-Sha1: 8367adb65e7d64cc8fb402a30e3d67f29e3050f5 2440 mumble_1.2.3-349-g315b5f5-2.2+deb7u2.dsc ff9a2961f4a2887d24c78825e82ab60b19f31db5 52370 mumble_1.2.3-349-g315b5f5-2.2+deb7u2.debian.tar.gz d35e01fe360ef88e88aa92138e612a03a05b83b1 2877702 mumble_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb 6d894145a6eac63ca79be55e522e99f207a51386 955396 mumble-server_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb 14fdb6bb340d45b45ffe41054d04e6318ff4052e 29371722 mumble-dbg_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb Checksums-Sha256: 3f9baaad5c768dd96ad485a4d3774dc8cee0659476d77a9f1e09555fad2bfd55 2440 mumble_1.2.3-349-g315b5f5-2.2+deb7u2.dsc e32addd16356749bbbfd77808509b78d39d6c7d9f6db0c48c7ac41d9162bfaef 52370 mumble_1.2.3-349-g315b5f5-2.2+deb7u2.debian.tar.gz 532e6545dba389055bb8152e9e4e66d9eebee97ee0beba20f5e105cc99268dab 2877702 mumble_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb 7b26f7481aabf5653c52f2eb04c53796ef216bb10d0e9ea8516c5a2ad89b5a57 955396 mumble-server_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb 9d6dd84ee24c83451d3766fe57ad3a82b453f93395803175f2de6f1cfd873fe5 29371722 mumble-dbg_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb Files: fb7dc7ebfef58f1f21857b31a9e5b05f 2440 sound optional mumble_1.2.3-349-g315b5f5-2.2+deb7u2.dsc b26f84ceedca1073c7bbca5b2681044c 52370 sound optional mumble_1.2.3-349-g315b5f5-2.2+deb7u2.debian.tar.gz 09e9b55d6b6b72b68061d952684f379c 2877702 sound optional mumble_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb 480d0235976f4bc965da6884ae1febd3 955396 sound optional mumble-server_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb 600c4eb988825047cebb4900807fe51a 29371722 debug extra mumble-dbg_1.2.3-349-g315b5f5-2.2+deb7u2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJURTrzAAoJEBLZsEqQy9jktgAP/18cCQfuOGkf4m5Py7Pg1Evy cuM3S/Xkk6naNAo7S9CWJd+XW338e/C4dwb1O2e4Ofj7ptZxPlsnjfo3JWkmKGl9 NKu+udKupEUf1ato3aMa8mXuxTld5tqcXhmpWxYcE3W+7rS/pKnGAFJTdFu5+s/g uSudSrLkpjmE7wKWsAmnm3abEtfN+DI4bpfTfIs/86WxUfjVGmdi9wHttPUGyR/z nAmHEdvcwTIeVKNPyJsqGuyS5MCJPa9vXnKJUADaUOZTLxQ1WKhvVXoYDoEUnlxP K7Q7o9qsc442Yq+OH6ERYvZtkMAIbJdJGi+X4Hje1G5krz9FEOQGCh8aeGFSoScY akBAaNtqyYfub7OMpboMa4AXDcMZrmosxL85Pfboc4/UMVSp1K+WBsWXgm4S31NE HKeBhUIS+UyxXPEitGSrQIKj6aca2/S4ssqWHQoW0vUJZpQYxIZiC/4hzk/KZxrl 2Of4OFWMRdahgaAfroPVZ6vtlHzHWGOPs03A5RUgN/xkkdwSe57HvFWfNyadGqIc qr7ACPbdsLQxTGPIlNPXj+jB6VqIk1fmwYJwH/AnMP4vYpABeL1FHKFyH9gZK1ed CrunrbPL3A8BoSFgzr7thgb3qMU3foFHcZcRgdASLRSW4fg9+Bax8SJioVIZQUIz HYgWQA2dCQdvTKej7xAc =FtJJ -----END PGP SIGNATURE-----