-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 05 Dec 2015 12:37:37 +0100 Source: tryton-server Binary: tryton-server tryton-server-doc Architecture: source all Version: 3.4.0-3+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Debian Tryton Maintainers <maintainers@debian.tryton.org> Changed-By: Mathias Behrle <mathiasb@m9s.biz> Description: tryton-server - Tryton Application Platform (Server) tryton-server-doc - Tryton Application Platform (Server Documentation) Changes: tryton-server (3.4.0-3+deb8u1) jessie-security; urgency=high . * Adding patch 02-CVE-2015-0861_field_access_on_multi_write.patch. Field access was only checked for the field defined in the first values dictionary, but it must be checked for all dictionaries in *args. - https://bugs.tryton.org/issue5167 - https://codereview.tryton.org/22631002 Checksums-Sha1: 70317ccc1e094c4cb7120ab5016d71eef366f594 1817 tryton-server_3.4.0-3+deb8u1.dsc c4c9f19cd3fd5536888c604930b75036a52e4d11 498268 tryton-server_3.4.0.orig.tar.gz c39d809936d8e42193d7d4317cdb94d2bfd011f7 29168 tryton-server_3.4.0-3+deb8u1.debian.tar.xz 6f3fde3d34be84d1e47cadda2534b6173de7a6d4 318374 tryton-server_3.4.0-3+deb8u1_all.deb 1d3f6c8eccf75558fbc9f8d472f955f01e5bdaeb 105156 tryton-server-doc_3.4.0-3+deb8u1_all.deb Checksums-Sha256: abbc126a173f23784feaba07e1daca1f073084da2c8003121eeb80bb7c567098 1817 tryton-server_3.4.0-3+deb8u1.dsc 78a62b0fd7701e90a3ca5ef71a1ef65cf9d9fe363a0f12510b8ff373ad16bcf1 498268 tryton-server_3.4.0.orig.tar.gz f06d0ffddbebe0f088020e83e7b94f1806457eb5ada80ffa0eea8ef079ee2bcd 29168 tryton-server_3.4.0-3+deb8u1.debian.tar.xz bb598a6c0e0b7b95ae42924b7e887777a6c587df68e86c6df90e1f1cb4a7794a 318374 tryton-server_3.4.0-3+deb8u1_all.deb 77af332b5a339443b8a0f04a84518ce5f7185cd9f31fb76349b85ef6a746eaf0 105156 tryton-server-doc_3.4.0-3+deb8u1_all.deb Files: 69726af7eda0bf26f96e09602c7dd024 1817 python optional tryton-server_3.4.0-3+deb8u1.dsc 0652ba23f999650b97e8a10dd3fea7f3 498268 python optional tryton-server_3.4.0.orig.tar.gz 2fcf2f9665d4b65613c4190ce61fa1c7 29168 python optional tryton-server_3.4.0-3+deb8u1.debian.tar.xz eae181970a2881af8d88a2637dd00e08 318374 python optional tryton-server_3.4.0-3+deb8u1_all.deb 2c0a331331078f6bd73edeb8da2f8989 105156 doc optional tryton-server-doc_3.4.0-3+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 Comment: Signed by Raphael Hertzog iQEcBAEBCAAGBQJWaJDVAAoJEAOIHavrwpq5ZEkIAI4DqQX5539pnIthB9xZdk7F 2lA2GWjR0PTCqwILffsbuMFSsJ2MomSRaXcUyGhlX39Iv9jOiC/l1yIYOYet+SWQ JzjJKvkTl2NvIxjqf2IrTyknkyzt2a2t3dwD+Myqd//IR2QaLD51IaB1PIn4Prdz Y8vXy5pnR899uAINhIvmcyNuazmvCsbBwabI07HnYgcm0z1A0f3sLfXl0L2PlQoI xuPG11Byv96piKgQjjPiwbaUoCPG8WD5QbYILdtE7OdfoeubU3hOPlAH83qhSAtt FAcywAun3XJ/izqM/uuHO5dWl7XKAm+9JVkfl48x49LFxogsVyYQP0QLGXz0ito= =SzAh -----END PGP SIGNATURE-----