-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 25 Nov 2015 22:54:54 +0100 Source: dpkg Binary: libdpkg-dev dpkg dpkg-dev libdpkg-perl dselect Architecture: source amd64 all Version: 1.17.26 Distribution: jessie-security Urgency: high Maintainer: Dpkg Developers <debian-dpkg@lists.debian.org> Changed-By: Guillem Jover <guillem@debian.org> Description: dpkg - Debian package management system dpkg-dev - Debian package development tools dselect - Debian package management front-end libdpkg-dev - Debian package management static library libdpkg-perl - Dpkg perl modules Closes: 785095 798324 799020 Changes: dpkg (1.17.26) jessie-security; urgency=high . [ Guillem Jover ] * Fix an off-by-one write access in dpkg-deb when parsing the .deb magic. Reported by Jacek Wielemborek <d33tah@gmail.com>. Closes: #798324 * Fix an off-by-one write access in dpkg-deb when parsing the old format .deb control member size. Thanks to Hanno Böck <hanno@hboeck.de>. Fixes CVE-2015-0860. * Fix an off-by-one read access in dpkg-deb when parsing ar member names. Thanks to Hanno Böck <hanno@hboeck.de>. . [ Updated programs translations ] * Catalan (Jordi Mallach). * Turkish (Mert Dirik). Closes: #785095 . [ Updated scripts translations ] * German (Helge Kreutzmann). (Various fixes) * Spanish (Santiago Vila). Closes: #799020 . [ Updated manpages translations ] * German (Helge Kreutzmann). (Various fixes) Checksums-Sha1: 4d26f56352980cbc57a78608a184b5a3c5ff68f9 2018 dpkg_1.17.26.dsc 27e5649d983cae956268207bce59a70fe6379fe9 4410860 dpkg_1.17.26.tar.xz fd4a781cf539aaf1295c7e9bf74a59e8d6519102 876250 libdpkg-dev_1.17.26_amd64.deb ceac73c668ba615aaa6b362d48442c357ea9fff5 2990646 dpkg_1.17.26_amd64.deb 6fc7417719fb0dcba5976fe70541deed3500188f 1138140 dselect_1.17.26_amd64.deb 255b9b778d564260af540c71b07d186c01c19504 1544868 dpkg-dev_1.17.26_all.deb c69b0ab1888620beda2bfb75b8cd5f9bd001e2d1 1071662 libdpkg-perl_1.17.26_all.deb Checksums-Sha256: aa6d4bf6a85bf8f469d64a5ec28a53486ab216c7d1dc87e05d8395fb4540cf33 2018 dpkg_1.17.26.dsc aa4e758752cdfd7ecb118d7a7d31139a0c090c92aa494aa2e46603006deb1ec8 4410860 dpkg_1.17.26.tar.xz 725690fb240417a05d9b6442c00e50a61f599764a91edab7e0ae25116ba50859 876250 libdpkg-dev_1.17.26_amd64.deb 95599abfb639919c49f45fc5dd2aa6b0cb9f9703c3d4eac4b5a5dee9c8bce4be 2990646 dpkg_1.17.26_amd64.deb f3f16a6ec68a4ad2b02b796340d3deca42fffa646b1b469006a7dd00165fd373 1138140 dselect_1.17.26_amd64.deb 3a831ae1b534677c664c84be3d3930720a7db32e9d177e27a5048ef807ef3113 1544868 dpkg-dev_1.17.26_all.deb 8871dcffccbdea243fdd5cd98b18895b7b9bee074be7fce7458a493f6e6fc174 1071662 libdpkg-perl_1.17.26_all.deb Files: 50037d0f2e9f98fe8fccae80aac4add4 2018 admin required dpkg_1.17.26.dsc 07911f1c575f196f108a3c19c5bd517e 4410860 admin required dpkg_1.17.26.tar.xz ad024fd557a6e958f18ac96a79328edf 876250 libdevel optional libdpkg-dev_1.17.26_amd64.deb 303a76790d0823abb91e88e6ea6a6a71 2990646 admin required dpkg_1.17.26_amd64.deb 33746c56b130230a079cc5f6c2d32044 1138140 admin optional dselect_1.17.26_amd64.deb 33f80c3a5bbab02ca909fb252ff0b91f 1544868 utils optional dpkg-dev_1.17.26_all.deb bf7f0c73d5e8e47c67f46e03e48571a7 1071662 perl optional libdpkg-perl_1.17.26_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJWVthdAAoJELlyvz6krlej29AP/RBtN+fseWtki+KIAtOqgSX3 EXeF8jwTBFsHDjGtumHryELgWcLHNdTVi+CXLSofhVz2GL8DkXewYUwEmmS7SaKn dFdtsJjAfEjDAJ87iUgqM4Iot9v6c/WfhNHWowvmQ1x0AyVwhymaTfM0JHmR2vWf VvXuUxlHulCkhsF0VGiP8+B93ruAooSCdnKexZzHR03L/mAPVUwXR3p3U5IZk5Yt Q/gannxhlbBgBucUYnRh3WV+DB7U7UlHYXk2wbQzY4QUUu7HfmblyeIZnhOdz8+s Q4+0vn2Ni6CMbRdFP/txl67QDZZgazWVJpQoapzk9OQQ4FO73CQ5s+utZm6bDPIy 2zbeGzUzX+AUiDVP2SYr4Vvv0wRU4hwf6beU40xjGit90SUZ2xy//iw7O7YokHZ4 eR4LMMVefHb0okS0HISHfZILfJaWCpI5YXwQH09mqLJY0OhVruxawn69HrU1z1vs j2uEAv+BPCfuzhuVDFnFV0IK4pVRMMFINaRZAi4fPnzEyAA5zD7Wwlbwt2d4a9GX ZpUNnXp2hkixR7vPK6fZkdIc/RSByZyQ+wqt4uyu5M4R3n4Kv4VbOzyppmdiTkcz mUR/LTolGh+CqpsyCMBeqn0l+flmo1KAKSP6WDRrAS3MGo2doQCsubntAKVjAMmV PMyNIxZb12mEmsUQQEON =G83v -----END PGP SIGNATURE-----