-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 19 Mar 2015 18:38:23 +1100 Source: autofs Binary: autofs autofs-ldap autofs-hesiod autofs5 autofs5-ldap autofs5-hesiod Architecture: source amd64 all Version: 5.0.8-2 Distribution: unstable Urgency: medium Maintainer: Michael Tokarev <mjt@tls.msk.ru> Changed-By: Dmitry Smirnov <onlyjob@debian.org> Description: autofs - kernel-based automounter for Linux autofs-hesiod - Hesiod map support for autofs autofs-ldap - LDAP map support for autofs autofs5 - transitional dummy package for 'autofs' autofs5-hesiod - transitional dummy package for 'autofs-hesiod' autofs5-ldap - transitional dummy package for 'autofs-ldap' Closes: 779591 Changes: autofs (5.0.8-2) unstable; urgency=medium . [ Salvatore Bonaccorso <carnil@debian.org> ] * Add patches for CVE-2014-8169 (Closes: #779591). When a program map uses an interpreted languages like python it is possible to load and execute arbitray code from a user home directory. This is because the standard environment variables are used to locate and load modules when using these languages. To avoid that, a prefix to these environment names is added so that they aren't used for this purpose. The prefix used is "AUTOFS_" and is not configurable. Additionally a configuration option to force the use of program map standard environment variables is added (FORCE_STANDARD_PROGRAM_MAP_ENV). . [ Dmitry Smirnov <onlyjob@debian.org> ] * Refreshed other patches as needed. Checksums-Sha1: d50642a1951f7ab4a017058ebd173ced462805c5 2344 autofs_5.0.8-2.dsc 3dbd50793c2c6ec4aa20429a7eba3840f70ea630 20056 autofs_5.0.8-2.debian.tar.xz d6130191367fc387a2eff5fefe682b92bb996a09 317150 autofs_5.0.8-2_amd64.deb f60a1aa720a1b068e3013cfd7ccd6a0ac0cd4b83 91156 autofs-ldap_5.0.8-2_amd64.deb fc4fc204c517c28a8ea156b78124154805cb64fa 73234 autofs-hesiod_5.0.8-2_amd64.deb 6d4258a23f25f245cd1de7efccfcd831a55ef80c 24238 autofs5_5.0.8-2_all.deb eaeec7eebb5b59caadc39c426089ea39108e79d3 24252 autofs5-ldap_5.0.8-2_all.deb ecd0ffcda3c0379f8bd370ce43f8e88490050409 24266 autofs5-hesiod_5.0.8-2_all.deb Checksums-Sha256: 99b071544fa3f8e2f9b2b16bdb9c7784eb2be01d6745d1e0ab487e26e38817df 2344 autofs_5.0.8-2.dsc 36690a9a6727b6a115ea866d17cee6c74b357763b33c3e3a46c3d1650da3a7a6 20056 autofs_5.0.8-2.debian.tar.xz d5dfe3f6a99063ecab66c1849b97140fa1bae10420dd51f47053f617eba23c09 317150 autofs_5.0.8-2_amd64.deb f7ed4cd5e9903fc6346386aa24033b76b30bddecb16899c6e376427e0c26b58f 91156 autofs-ldap_5.0.8-2_amd64.deb 11166f1521fce77af2169c3274dd5f91c426fcc7433d613c610ecb8b47d46ea6 73234 autofs-hesiod_5.0.8-2_amd64.deb e27fe744c636808c0cf932dea2b7d671d72d55b96475622031acf263c4b5ed2e 24238 autofs5_5.0.8-2_all.deb 53d58dbdc90d9edbe50890dcdec106ed094de264ccb4b05d4c1427d6e12656b2 24252 autofs5-ldap_5.0.8-2_all.deb 56504aa36c1a7297232b6fa4a11e3bd708acb1641d914ed14ed7e13b3c90af85 24266 autofs5-hesiod_5.0.8-2_all.deb Files: 13ea38db0ab27ab3a612ecd9bddc9d40 2344 utils extra autofs_5.0.8-2.dsc 6fc256838c434bc361f50181119cc933 20056 utils extra autofs_5.0.8-2.debian.tar.xz 8c583096285585d58040e28c4a2fe03e 317150 utils extra autofs_5.0.8-2_amd64.deb ff805c3d8f426bca37417dc2797ab279 91156 utils extra autofs-ldap_5.0.8-2_amd64.deb cff74ecde911d4f635d6d2eb541a1d67 73234 utils extra autofs-hesiod_5.0.8-2_amd64.deb cebd4fa1fba91e703987d6f657ac6f20 24238 oldlibs extra autofs5_5.0.8-2_all.deb 23ff1ed10dc71f18d18568ebf79b4c65 24252 oldlibs extra autofs5-ldap_5.0.8-2_all.deb dd9fe8d3fc11e5d93bcf1df7fc446b99 24266 oldlibs extra autofs5-hesiod_5.0.8-2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJVCoWeAAoJEFK2u9lTlo0b79UP/2UcgN33dZPhe/DWDnw/GDVG 0fc8zDDxChVItr4LyqdmztU5VMxwUPMV4NaPJXDXp+MDv4rel0BO22zSzymUL+B7 AloIZoaPsaOnqiBflOXNDrmiC4DecLTIuvSvUpIcaPgHG/vqsCvUu9kuYQrZt9VK y+838sjbXlJBcGR4AWvTz0zb4XvggSagQKsnNgyIazKB3D1SRIkKzBMZAiixLSDb CgDM0kSAjJM0aI+oWxHQFNlzyAi5MO2JpEQ+D4yQ94MT1z2RSO0uLwK71J2V3tiU mANvvaDBH7rgD3SDD6g5b2MAmgIIAl42P+TvSJAJDVAhkHU+0TPOwYZR6wvM969P TAmwgGN01V3FKkxomJVaZMEShaDG3dehoJ4ZujvCWjXammkxMwju4dXNw2BpvPjC nZCkmI4jh4pmVUqW05cKhhWKIO2NeALKBSevW2/taGFhCcGbKYs4kTAV0GkQm/zP gISr9hzY7IEhO0K77TcCkQs7Q1b583v3OzzshAKl3w/UFcljj5ot15zD/MtK7oRo Fv5GFK2SLu/MZpb3VhG0mBDMenakCqDzOAC1Xy4V6B8UO/PptDU0T2ePkOc6pRIZ H6ADgkURlbXdPKTX+B7UqtnSKW0ZDmfuq5CzyUev/LMSFJAZcDyxuUrRUxSuZjoU IYkyyDEoHAK/dZIjloDP =3uY/ -----END PGP SIGNATURE-----