-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 28 Dec 2014 14:45:59 +0900 Source: mime-support Binary: mime-support Architecture: source all Version: 3.58 Distribution: unstable Urgency: high Maintainer: Mime-Support Maintainers <mime-support@plessy.org> Changed-By: Charles Plessy <plessy@debian.org> Description: mime-support - MIME files 'mime.types' & 'mailcap', and support programs Changes: mime-support (3.58) unstable; urgency=high . * CVE-2014-7209: run-mailcap shell command injection. Thanks to Timothy D. Morgan for the report. . d156797 Escape file name also when not passed through %s. This avoids command injections using for instance semicolons. b585022 Resolve file name to an absolute path to avoid injection of command arguments with file names starting with dashes etc. Use File::Spec to avoid race conditions with temporary files. Thanks, Salvatore Bonaccorso for the patch. Checksums-Sha1: bd04699c9c4df5fa08e0da5e74d92ff9977221ab 1604 mime-support_3.58.dsc 5e8c8dc952aee1adc589dbc1a2526f3eb83fd293 34995 mime-support_3.58.tar.gz ad875319f0048ed742d3cb60f00d437a7db98790 35994 mime-support_3.58_all.deb Checksums-Sha256: 3279480870a7bd6c7e2a85f7f1e5deba50c3cb5edcbd6ce69a3cfc7fe0266284 1604 mime-support_3.58.dsc 3d9ca5115e93edb3ada3fb120cde88ac3d866903e18a41ca124428d77dd1721e 34995 mime-support_3.58.tar.gz c05ebe8f38da4ff19d028c9f4680414149e5c7a746de13bc9db0a562796ed213 35994 mime-support_3.58_all.deb Files: c63a0f86e02b1c0e382f5d72e89138ab 1604 net standard mime-support_3.58.dsc 461430b0c9356ff3d7b0f0b61f9edf53 34995 net standard mime-support_3.58.tar.gz 81e70b10c1aeaa6e54eb436c842b5501 35994 net standard mime-support_3.58_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUn6c+AAoJEMW9bI8ildUCNKMP/iOjAbvO0F0yQf7pZXgYJkGC GDw4jMNjuQjDMPRqDdPsJAcZYXT76n8uVY0uLymwUgzhQrscI5HpZSYPn/jC8OgN 80aETzimQgZGg+kwgcDCkt+XyRwPc+6JXR8dLvzdDWRLoccFzbbSo3+z13xwb+uf Npp6TaKK875oNInRvY1lS3zqGghMY6JQJ2c0SzsUifN3zpkWszxJomeigkTu3gBh hFjGIL1yst/DqYEMcPgKhMk+4yBG0tSZBmQRAuYV0xhcFyJ60f2ItYSj0JulePLD oFDCwdUtwuSZnwzk3I6V+vlZqBJihxPOD7ypXcsFGBtjX4dsAuFiGL89jCGL50Ft 5bPt80ELu8QlBNQKDiVCoeVkVeI1tIQx23FTflhyw5FbxSYyXrmN88ynK6e7ot7e WJypwQQTkwMbphcyrvVRzqGDyyLQok2dn2jpUNylDe3ImGdOGwRWkEh/0kII1hqI qGu5q220TNanG05D6a9BuVCB/CWGuYvwrX8JuKKGAh1Y9MmVO447oMF+fp5eooFV DLaN7y6LEyTU65RgFVjIMY/4JxCwO8BUzSXcYEwIw26jLSTgMxC4fU93WpOjBr14 XQUXwNyaxFEz2UPoHVg0VI8qe75ts71iVimKGYk/j6HZ/zlnItbq50DXcyYrpAHE 8xkr2FzrrNUYeimiMW5u =iq5v -----END PGP SIGNATURE-----