-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 10 May 2015 16:41:30 +0200 Source: quassel Binary: quassel-core quassel-client quassel quassel-data quassel-client-kde4 quassel-kde4 quassel-data-kde4 Architecture: source amd64 all Version: 1:0.10.0-2.3+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Thomas Mueller <thomas.mueller@tmit.eu> Changed-By: Felix Geyer <fgeyer@debian.org> Description: quassel - distributed IRC client - Qt-based monolithic core+client quassel-client - distributed IRC client - Qt-based client component quassel-client-kde4 - distributed IRC client - KDE-based client quassel-core - distributed IRC client - core component quassel-data - distributed IRC client - shared data (Qt version) quassel-data-kde4 - distributed IRC client - shared data (KDE4 version) quassel-kde4 - distributed IRC client - KDE-based monolithic core+client Closes: 783926 Changes: quassel (1:0.10.0-2.3+deb8u1) jessie-security; urgency=high . * Fix CVE-2015-3427: SQL injection vulnerability in PostgreSQL backend. (Closes: #783926) - Add debian/patches/CVE-2015-3427.patch, cherry-picked from upstream. - The original issue was CVE-2013-4422 which had an incomplete fix. Checksums-Sha1: 97dc462a38f5afe2ee40ba9ea1c5f1cfbe0305b2 2386 quassel_0.10.0-2.3+deb8u1.dsc 305d56774b1af2a891775a5637174d9048d875a7 2873233 quassel_0.10.0.orig.tar.bz2 45b85dcf01d3916016c0b15aac6927d53f53993d 22704 quassel_0.10.0-2.3+deb8u1.debian.tar.xz 6b4d3f4a2df4e2e3fe95a6207077ed173a6cbf29 1646958 quassel-core_0.10.0-2.3+deb8u1_amd64.deb e4b0f176b2e56e10ccba05612073cd4dc36caa9f 2438518 quassel-client_0.10.0-2.3+deb8u1_amd64.deb 749d6341e75dfb89c1ec8384668c3bfe351270df 2849324 quassel_0.10.0-2.3+deb8u1_amd64.deb a9cbbdef40217aef0a1a6f0f0d58a8ca1c635f41 22954 quassel-data_0.10.0-2.3+deb8u1_all.deb 0ca6ad22b3492ef1faa3cdb46e0f3421f90506ee 837076 quassel-client-kde4_0.10.0-2.3+deb8u1_amd64.deb 087fc90daa18f30f35291479054d989929c3222a 1076750 quassel-kde4_0.10.0-2.3+deb8u1_amd64.deb 27b9c812ba7f5cc2bb9b86e9b9cd167fff5530ea 623590 quassel-data-kde4_0.10.0-2.3+deb8u1_all.deb Checksums-Sha256: 49e1cf9fbc0c6a14d8dee6a48e7a7ac829525a8203e7f804dd0d0122c5908f71 2386 quassel_0.10.0-2.3+deb8u1.dsc 68228ce23aa3a992add3d00cb1e8b4863d8ca64bea99c881edf6d16ff9ec7c23 2873233 quassel_0.10.0.orig.tar.bz2 0aceb0c8d53dc194f2894e1f877d2313dd1e968042400b3daa40e08a26a47e58 22704 quassel_0.10.0-2.3+deb8u1.debian.tar.xz abd46b32a429eaf1acf78a868907b9fd5e5c08e0b13b6d41ccd9192e12708af0 1646958 quassel-core_0.10.0-2.3+deb8u1_amd64.deb 076a97dcbfdbe6a00e0d7e03d8ecc1c39ea2f485b4249390c0b4334bbdefffb3 2438518 quassel-client_0.10.0-2.3+deb8u1_amd64.deb a9269d84b221bacdf3fe2ab6e5e171116fffac5fe2db8c85bc6e6f9097f25d9a 2849324 quassel_0.10.0-2.3+deb8u1_amd64.deb 94ea9dd74601523727dc6beb8b0668d077a384bfc4eee966578c7f214670d292 22954 quassel-data_0.10.0-2.3+deb8u1_all.deb f91ad19cd3e0bed86fa1ac1d234f27fea5d92bfd18778f32fb3759ece419b4f1 837076 quassel-client-kde4_0.10.0-2.3+deb8u1_amd64.deb c9554a453e9196953dbed008829bc1d9160e4593529e70d81a65be173b4e2bbd 1076750 quassel-kde4_0.10.0-2.3+deb8u1_amd64.deb a704b2a45580ae2de7994876ca131c396174e56cdb957461f76550be40a95e1b 623590 quassel-data-kde4_0.10.0-2.3+deb8u1_all.deb Files: 0385beb11574e9757a123d7d25fc3777 2386 net optional quassel_0.10.0-2.3+deb8u1.dsc 382466a7790979c172b7d7edf10a2981 2873233 net optional quassel_0.10.0.orig.tar.bz2 bc36915aecdb9415595a9e64f2bfbcde 22704 net optional quassel_0.10.0-2.3+deb8u1.debian.tar.xz 87b581b01dc2fc46cb8eba3887b028c4 1646958 net optional quassel-core_0.10.0-2.3+deb8u1_amd64.deb a8f0ba96727e72aacb9f4da15268cc31 2438518 net optional quassel-client_0.10.0-2.3+deb8u1_amd64.deb e6eb929c8a82e1696dbc4ac808b46ece 2849324 net optional quassel_0.10.0-2.3+deb8u1_amd64.deb 4c20c2ffc255d7384bb4894d2ad74536 22954 net optional quassel-data_0.10.0-2.3+deb8u1_all.deb f2e9c0c21f3a1f799e5c7a197f4041bd 837076 net optional quassel-client-kde4_0.10.0-2.3+deb8u1_amd64.deb f48a4fa79b58ab55eccec662e69cd9de 1076750 net optional quassel-kde4_0.10.0-2.3+deb8u1_amd64.deb e1c54b6b449111cf88ca80958f3f585c 623590 net optional quassel-data-kde4_0.10.0-2.3+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJVT3cfAAoJEP4ixv2DE11FQiMQAIKXdj0QgiJx2fVXbhmNY2Zj iroZ2hG40u+8D9Lt5YQamtaBgzcJf4jSVAwVTzvxQxtqma/peMBPj6LjKHi6/Zpb Q1lO2N6o/otJxia2hqG3aAu5o05772dkiIXyeowEdYh7o2Y1QjdJHjQZ9i2kuVdb qxRiPP438Nw6ztTlPCsYTCfneBuIRPOyA8Eiz42FdNpTYU7R4aTfuSonOYa/RODA vucsG1qfXtbEU821hgWuCJQuaqqhUQ0cHEb/1Bq/skMHd5L3rkW+3qNIx+/BVOc2 zv8eXDBKN589SNI7vqgLcjyjKeQ8mcH4yAjFLpfAqK6nZHPQuTUdsgSRMPpkJTsg fgJplUOmV/+XMhsTr1JA4buFFBgzoyUrUiPJ5NvsUzBRDGRZmhWC7yeYOxfHW+I2 DpRVvCITTp+fMZkZp1V+urvBILbcKt02mdXitArQZLAZU0K819QDlS2TkWyGuW82 DdRtNvHY/4ubDVJozThrNYwZRzcJm39cK7VDUK7+mXKVhbsepy88XnYnPf2La4U1 BlVJiQFdgphyrnfl2uVC/7qxnQvgYuBMtk3Dt35Kt7TTJhYDBFo3PPrxg7qyA1D2 2rCivMmbCM04d5hcWXBCW/DKjpYrqFoEIZEThRSWAuGE2UkDaFfaXIfetocurn1Y 3UNynaWMm9p0OIPdlCHh =SwFw -----END PGP SIGNATURE-----