-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 07 Feb 2015 17:44:28 +0100 Source: dulwich Binary: python-dulwich python-dulwich-dbg pypy-dulwich Architecture: source amd64 Version: 0.10.1-1 Distribution: unstable Urgency: medium Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Jelmer Vernooij <jelmer@debian.org> Description: pypy-dulwich - Python Git library - pypy module python-dulwich - Python Git library python-dulwich-dbg - Python Git library - Debug Extension Closes: 780958 780989 Changes: dulwich (0.10.1-1) unstable; urgency=medium . * New upstream release. + Drop 02_unpure_pypy: applied upstream. + Fixes CVE-2015-0838: buffer overflow in C implementation of pack apply_delta(). Closes: #780958 + Fixes CVE-2014-9706: does not prevent to write files in commits with invalid paths to working tree. Closes: #780989 * Update Vcs-Git, Vcs-Browser and Maintainer fields to reflect the dulwich package is now maintained by the Debian Python Modules packaging team. Checksums-Sha1: 885177c9911817599c188571eb439de950b1ead8 2275 dulwich_0.10.1-1.dsc 57f1f457be3065bac6706db2aa76d59b078597f9 272688 dulwich_0.10.1.orig.tar.gz 88be5619497a18ba0a12b05f883bb3b1bdf61fd4 405512 dulwich_0.10.1-1.debian.tar.xz 987d8142483ab0b4dcbd3a9f573d75889fbcacbd 202868 python-dulwich_0.10.1-1_amd64.deb eede404400cef3427bfbd1650d9f1a32860ad555 96880 python-dulwich-dbg_0.10.1-1_amd64.deb 8cd1adb8c28071cd2f22059f71b2b1530a281c18 203256 pypy-dulwich_0.10.1-1_amd64.deb Checksums-Sha256: 0f8d7ab6b9263103ee95c3088fa8cf65eb79abd0ff377ae572e96c43dad3ac01 2275 dulwich_0.10.1-1.dsc 666600ab5eb0b6d531879ee0f65dfefd71bce2e21ab3910c28f7789e15b6330b 272688 dulwich_0.10.1.orig.tar.gz 9c27f5ec25f0aea96f4ead69e7ba6673173132032d029f918011b2242047cfa6 405512 dulwich_0.10.1-1.debian.tar.xz 4854789a05f856cfa94e7b1fd4e4a475a9fd37bef62d9076984838274b4fe426 202868 python-dulwich_0.10.1-1_amd64.deb eeb366cf32176d7e6651bb2f25ea527acd03b98e2911879a85dbab423a9919fc 96880 python-dulwich-dbg_0.10.1-1_amd64.deb ab84e3bd24130348fe66813c962fe2ebc9c9dfd9f0ee28a9dd48024329b861c8 203256 pypy-dulwich_0.10.1-1_amd64.deb Files: 0c71f3af5046ff48c763a6ecb00a83ba 2275 python optional dulwich_0.10.1-1.dsc 93a5facd51f3d7de7224a1a832f3a3a3 272688 python optional dulwich_0.10.1.orig.tar.gz 83538a637bf721f69f9bb9bab7186acf 405512 python optional dulwich_0.10.1-1.debian.tar.xz 6fd5e579f38cde2b9c1914fb7e6812ac 202868 python optional python-dulwich_0.10.1-1_amd64.deb 86804020f33e559e53cd48fad1e0ebfe 96880 debug extra python-dulwich-dbg_0.10.1-1_amd64.deb c2d6861cbe45153e8c81cde1d52c5d6e 203256 python optional pypy-dulwich_0.10.1-1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJVE+kIAAoJEACAbyvXKaRXzkcP/ApqyyPoz57LUz3ZySsbNOii JpcEn/I+4y/x+n2d+0Uz4/0BBpbvsnV/WyTpZPhJv59qLJ1tJDNBuZB13sL8DXdK iPfwyH5qQi6rRkztwd2CCUxbe7czDiKuYw724jkFG1XDICtvPsP6IG8Xn3pv1URc zNFR1alGp/SFiAKjLI61mmmBf766dAvLDqQmYG30vsWnhwueUdSIFXSA87jdoCu2 fO8ZgMasA8B69szJ8CFCPuFAUnXILipppg5g/8Y15iRwx3r0mvYWJclGv/Qi7tNP kpZTrgIE7hCuZ1jagA0JgS5+Z1+Bc2wjBmOTAeZRzDRKxqTN/6pymGuEOdyTo5Gv kgtx1R1hu6KH7nJFzgNJBgZ+5M0WJQa/RoizE1IGdDlnyIkPKajvY9WLIb5q/Q4T Cjm0CwmERXjeY8QYZ4ELdL6KnmXt2GlOlkce6m8c9P6xAkg7o0c9OmrTxV2OKVTy opxshJxVVxhYMMetPYbMLlObyWQvPwq5wQFuyLCqwjZbnlMVIZQhQebqhPyAYP+Z 7qwzQchSgTWub0OnUue0V4oCGOihtqqr4qKqXBokX7i955zLSgx9vVOJeq/PFLG6 Dh/N88FInvw7NiNE9xZmwswkebas6hetriUgNIt8mRZsqBo74ea8TT9JNM9RVnU0 18S5e25KJ2k8x74jpsAc =Kt1n -----END PGP SIGNATURE-----