-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 27 Mar 2015 13:18:17 +0100 Source: dulwich Binary: python-dulwich python-dulwich-dbg Architecture: source amd64 Version: 0.8.5-2+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Jelmer Vernooij <jelmer@debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: python-dulwich - Python Git library python-dulwich-dbg - Python Git library - Debug Extension Closes: 780989 Changes: dulwich (0.8.5-2+deb7u2) wheezy-security; urgency=high . * Non-maintainer upload by the Security Team. * Add 03_CVE-2014-9706 patch. CVE-2014-9706: Don't allow writing to files under .git/ when checking out working trees. (Closes: #780989) Checksums-Sha1: 4bc0f7ba75029a7fe240e142c94c30b6aa972ce0 1993 dulwich_0.8.5-2+deb7u2.dsc 6517746d273df7015c2a36791b8c06937e38c649 6447 dulwich_0.8.5-2+deb7u2.debian.tar.gz 59fe584fc5e9ec2cefa2d0a622be916504cfe0db 193408 python-dulwich_0.8.5-2+deb7u2_amd64.deb 9890ab04502db6c9a9776b150967e4c34f2acd9a 107546 python-dulwich-dbg_0.8.5-2+deb7u2_amd64.deb Checksums-Sha256: fdecc9bbb327615594f2850a0ebd09c25a2238c51fcac1d4eff47e52e628945c 1993 dulwich_0.8.5-2+deb7u2.dsc a438a3d06f90698dba5737b8589652ada3723065aafbf0b55132ac3015a939f3 6447 dulwich_0.8.5-2+deb7u2.debian.tar.gz feb4b1c846e34bd754c3d1ba6d2859647b45e224364333217698a2c53bce2ee4 193408 python-dulwich_0.8.5-2+deb7u2_amd64.deb 983494cb26d73bb806e058fe55e22420a7872928d02aa2fc41f4b896ad240e11 107546 python-dulwich-dbg_0.8.5-2+deb7u2_amd64.deb Files: f961fea575c4d7d1225bfa1ce133c0ed 1993 python optional dulwich_0.8.5-2+deb7u2.dsc 920fc0d103d20f3f96232fa859603fb7 6447 python optional dulwich_0.8.5-2+deb7u2.debian.tar.gz 317e8c63f635c607ee8243ea6ed25630 193408 python optional python-dulwich_0.8.5-2+deb7u2_amd64.deb e49247ae3a72bcbea4eb262e2f3fa5c2 107546 debug extra python-dulwich-dbg_0.8.5-2+deb7u2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJVFUt0AAoJEAVMuPMTQ89EZuwQAIZ2ORbeJKpQCiE6LOsRZG9V AZWIvjpWLzU0QGKUSh4sDHgyPA9n64DBXHJB1eKiVLHchnzbqctvu+RBiNywY6i1 ObPWTVFkJidg/JZStsQYqMcg+J+2Ra8h6adu6KLx2+DC9oWcyhmYFkaVBTGQx2ux Vn72+NJRlFBr3KRKkLl1lHtrtjf6X9EhLYq+DMd2yRGGwFasojBF7pbh21xQcTss 3Kpf3QHlOYy1hv38KmERCEJNXhh5h5j0njC8bRQWPE9wdZSMcr2Mj5tiUjvqfM9f hP/m+xZsWlB11aYjFZ4Yj5c7YgGn2uW6CsKsiXtqMx6bcRGhcaPzlvkDBwhgTfV7 SttezujOvdm9DpdDbpzRLzoRotP4AFF3mNJMzEWHhHVKEOvniTi4r124mVn9hTQG yTv8R4R0sJDFh0VAAMSjzFOA6cKW5I8nLPluQm8JsL3lpOarXRE0Cv9mW2nWdW7B nCC+k18KUtUkER36tDeF7y01gebf3Wbbqcv4U8t3IUV1E6vomy6g4huqU6Y5qeHO jxx2rmCglJgn9zsSfv/cG2qLLrgy8/r25OMnQp8nTMjfiMyki69Pni+ZmX0uu8xU uA3NEkOsYOcCXd/8b6tAWx0bynfPKh0PInENDKgkHWzoJnxCdbJL2dJL5Kuyc497 SSPO/y4gcM7OHNgsNohO =WGJh -----END PGP SIGNATURE-----