-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 21 May 2015 08:03:53 +0200 Source: fuse Binary: fuse fuse-dbg fuse-utils libfuse2 libfuse-dev fuse-udeb libfuse2-udeb Architecture: source amd64 all Version: 2.9.0-2+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Daniel Baumann <daniel.baumann@progress-technologies.net> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: fuse - Filesystem in Userspace fuse-dbg - Filesystem in Userspace fuse-udeb - Filesystem in Userspace (udeb) fuse-utils - Filesystem in Userspace (transitional package) libfuse-dev - Filesystem in Userspace (development) libfuse2 - Filesystem in Userspace (library) libfuse2-udeb - Filesystem in Userspace (library) (udeb) Changes: fuse (2.9.0-2+deb7u2) wheezy-security; urgency=high . * Non-maintainer upload by the Security Team. * Add 04-CVE-2015-3202.patch patch. CVE-2015-3202: Missing scrubbing of the environment before executing a mount or umount of a filesystem. Checksums-Sha1: 016c06badd4c97bdb9fe4717a32f10a8efec4cc9 2027 fuse_2.9.0-2+deb7u2.dsc e64396d516cca55995e0a8f8dd75456fd9d9d21d 558554 fuse_2.9.0.orig.tar.gz c30f71bd86391d362cd5e6930eb6765b5c26a53b 16946 fuse_2.9.0-2+deb7u2.debian.tar.gz cb014668982dd3d84c834cc48acd445e5f330a33 74216 fuse_2.9.0-2+deb7u2_amd64.deb 15c834bbe6e8b6858a8824e8d69a8aed476b225a 328078 fuse-dbg_2.9.0-2+deb7u2_amd64.deb f4533a74982fa60f368cf86bdbb992044733d986 44138 fuse-utils_2.9.0-2+deb7u2_all.deb 5bdcc6e027ae17341a937937af66c22b8259178c 144202 libfuse2_2.9.0-2+deb7u2_amd64.deb 1e832115a0f49bd816f36c1cfb4a3ff088f9d939 176916 libfuse-dev_2.9.0-2+deb7u2_amd64.deb fa66076778810ba3bd3bbfda83fc8e9f822a725b 14642 fuse-udeb_2.9.0-2+deb7u2_amd64.udeb 42954d3a5c8a4dd03dbd3848d6b2c8bc6b2b5860 65244 libfuse2-udeb_2.9.0-2+deb7u2_amd64.udeb Checksums-Sha256: 319f00cc0b7a34aaa35a90fd16d47ae67100264422f56adcde851a4232b1190a 2027 fuse_2.9.0-2+deb7u2.dsc 1bf669e5388d4f256c7875079d5a6b97837bad23eb77a1cbc8b54b46a88315f2 558554 fuse_2.9.0.orig.tar.gz 9b9394e435057198c3f8c3095f0e0bfdcb2f61362d12958979be962fc89710c1 16946 fuse_2.9.0-2+deb7u2.debian.tar.gz 28b1f291860c8569b29734ec0323575274132816171d01404e03a646ecd3cc83 74216 fuse_2.9.0-2+deb7u2_amd64.deb ffc21a300cda5359d495ea8d9693bca33bb4610851be7e07ccd7e96d063ab3da 328078 fuse-dbg_2.9.0-2+deb7u2_amd64.deb d6fc3100561d02eb04ae1d6e01db6b9002c1e99c317c874d3c2fb27939e97eba 44138 fuse-utils_2.9.0-2+deb7u2_all.deb 54552fc2caf1c5c63a330c477b7645103e59259fe5a0a5327ac76a75f0e04d7e 144202 libfuse2_2.9.0-2+deb7u2_amd64.deb 1a2182f936907547aafc14e08a4dbe46354a837afd30b1bdc55492126c22c20c 176916 libfuse-dev_2.9.0-2+deb7u2_amd64.deb a6ed43c4a2695dbfd32be632fd0b88362cb660963e46a654a9ec47dedd000649 14642 fuse-udeb_2.9.0-2+deb7u2_amd64.udeb 7e4041aaa4a2bac3d21ae7af408c0a95ce5cb289afbb177a009748dcc91b0009 65244 libfuse2-udeb_2.9.0-2+deb7u2_amd64.udeb Files: 1cdeccfd6da9693cdedec2183b82f377 2027 utils optional fuse_2.9.0-2+deb7u2.dsc 894ee11674f89a915ae87524aed55bc4 558554 utils optional fuse_2.9.0.orig.tar.gz 465c760fe0aa1bdec00ed6ee3333a23a 16946 utils optional fuse_2.9.0-2+deb7u2.debian.tar.gz c05fb0f0e52913d80b41abf899f2c442 74216 utils optional fuse_2.9.0-2+deb7u2_amd64.deb c67f5f17b568d3d6b86d8910d3595cf9 328078 debug extra fuse-dbg_2.9.0-2+deb7u2_amd64.deb dbb33e74e0fb30034f2e47c64e0a9644 44138 utils optional fuse-utils_2.9.0-2+deb7u2_all.deb e9a3ce8c812830d82084fafe91c95f44 144202 libs optional libfuse2_2.9.0-2+deb7u2_amd64.deb 66510617995725a0b050165b7f9cdecb 176916 libdevel optional libfuse-dev_2.9.0-2+deb7u2_amd64.deb 31bf5bac67eb8b8ae532bb0edd4db471 14642 debian-installer optional fuse-udeb_2.9.0-2+deb7u2_amd64.udeb 55f299837a69799dc9b8b870cd62ad73 65244 debian-installer optional libfuse2-udeb_2.9.0-2+deb7u2_amd64.udeb Package-Type: udeb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJVXXXiAAoJEAVMuPMTQ89EMhEP/R1RdN1EB5o9LpmRjopRoakq tN4WydTa/9F5iBZJzurRrsnA8QrJ0Q0F1xINBbHkFSsN41eF3vVAg2LWd/ciCrXZ Y3lfA1MXfj1Zdf0iyuRe3iZUrsBbhb5nvTIn+5lqUFuOW+j9gyoglbGt+MMwkQ+4 m6j4IxQEFpIjRifxgkhz251jYI8lFqSWcARd8iKnO0q4p31/Uwb4erFX0/ntP4LW 0qdwuMG9B8WmciXhVgeLxSewUPSJsnEvbrSzh/Ht/mtsYyi2J8eF6VRTXiXjICH/ YjgQoSVLWw+z5h//tWnET+mFsmbkRDGWBqfjlEn+78QX1MYa3fbBdkdbQByIsQmz 7PF4OMD7mXajdib00es9sy7Wqv7isTWM7+CId9nFVuEPSLjoh2SS0E2wXF+idj9t r43WtQBUhf0l3dxTqOm5drLDPZ3v/Qh3aAxYIBYQKaeoV7/d+Or9n2CeIC67JmZ1 j0XBl58pXePwyNZz+ehxDX1CmrXEqg+6izse3PkpqB50kBleEil0AIccErwf//fr pa+qSC1u9zQPvWcZHIAVOdH8GEy0gK/eG6Fl/KnSWf3eAS3wvARS0VaYLEDfH91B Qogsg3fopQwItiXwqLIMvLA4JCEZ/4mbvaCLhcSylDc9Jm/O8BW1Q6jdRjDtRl5e EE+j9LK9QKYds5ipiqYW =h81i -----END PGP SIGNATURE-----