-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 May 2016 10:46:40 +0200 Source: tardiff Binary: tardiff Architecture: all source Version: 0.1-2+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Axel Beckert <abe@debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: tardiff - Tarball comparison tool Changes: tardiff (0.1-2+deb8u2) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * Add fix for shell command injection via tar filename itself. This fix is as well part of the CVE-2015-0857 assignment but was previously missed. Checksums-Sha1: 0b25fefa60ed854e11b87951f619fd58b52c1732 1823 tardiff_0.1-2+deb8u2.dsc d224995d662b11e2b14bcea174bb2be328cac132 4848 tardiff_0.1-2+deb8u2.debian.tar.xz 69f2f8f3ae96a181c3d7b29918a404d3ead8617d 5558 tardiff_0.1-2+deb8u2_all.deb Checksums-Sha256: 9f82d8936366900fe18c3293f191bcb6c00b53859ba7f48394b3ebb16e6199ce 1823 tardiff_0.1-2+deb8u2.dsc 038a5831da7f225b2e25e5d6ae00317eacc998a124a52cf3c1212eb270f17d22 4848 tardiff_0.1-2+deb8u2.debian.tar.xz afe880f71f634fd5abb9721334a085e8d4ba0fd4993c73e768e56758f5f7976d 5558 tardiff_0.1-2+deb8u2_all.deb Files: 28943645743c204e50e82a44686925e0 1823 utils optional tardiff_0.1-2+deb8u2.dsc 29425a40caa69cc1a0fc3cd2f7ac0a8e 4848 utils optional tardiff_0.1-2+deb8u2.debian.tar.xz 18874b170b57bf76c900bb3daecf38f0 5558 utils optional tardiff_0.1-2+deb8u2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJXJcM2AAoJEAVMuPMTQ89EVIcP/A6AD8XOo0G0lXbjH2zL3rwn n72wBXmtnacr63GD9EqmoGb8AzAgUTO4Xr/YPDN1IuySrgQtVsH4PGjG18aYCVNW 9tEFdwTNLXnqVjL3D9xD1+b5WiIdGkZAVp7U48Kh3GOLAY3pPS7O6LE3P4UcjZoF 81YBOQ6ugOBtyyLNa4RDEXijs8HznmtP8fwAwf0ZVhC2iNP8LpX+nTIvSK+jLzHX xIDqaqXyGsSoaFOdOK8Ji1lnN4/WvW5XZsYi7xpEdhRiNocn5HR+QQb77PUs+ndb 1pCSbtTF9fW5QtDsxJU22j0KX1Xl1fOWh6fP5MUmINHk1+qFesCTVbQopfxRr4CR ZMo/A0Zsok8XkZc6Ph4BHCZcVZn8BFJ/+wYfnYWEnAEAIauvC1qDASr6GIlY/81b WxnrekWU/+B0Vixh3xaivC5g0+MF0grOW3S6x7XRxbaBUquiT5LL7DX/9fURTGVt ctScrx2D8R69Wge3gNsJrr7+JYqrRMMv/MGy2UMuFA+cUzc9gynyAnRaIlqf7lHe Q6uMYzpiKDN3+HwdGwPAZsQHgytD6L+cqKx+MaiFC2z89Y5zX/2LlwiFwbv9yNVa XruJyL1xqOi3yp0AufaLu3PH7nTVLemb6RofvTslzqDPm1A16l95rJaagyEIpi4u TRKQTI7kGkX/4zRO1Zdv =O75l -----END PGP SIGNATURE-----