-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Aug 2016 14:58:56 +0200 Source: tryton-server Binary: tryton-server tryton-server-doc Architecture: source all Version: 4.0.4-1 Distribution: unstable Urgency: high Maintainer: Debian Tryton Maintainers <maintainers@debian.tryton.org> Changed-By: Mathias Behrle <mathiasb@m9s.biz> Description: tryton-server - Tryton Application Platform (Server) tryton-server-doc - Tryton Application Platform (Server Documentation) Changes: tryton-server (4.0.4-1) unstable; urgency=high . * Merging upstream version 4.0.4. * CVE-2016-1241 Prevent read of password hash. * CVE-2016-1242 Sanitize path in file_open. Checksums-Sha1: 66868d5614919a5bc7ca650328c8c4467999a32c 2238 tryton-server_4.0.4-1.dsc 403076229dac227a264b12faed87456286f9004e 602383 tryton-server_4.0.4.orig.tar.gz 92527adca5b6a88f4b4794ff0ab2051e61631f7f 39140 tryton-server_4.0.4-1.debian.tar.xz 4ccaf33e2d9afaf75bce26d4a991d5caaa75c39e 112488 tryton-server-doc_4.0.4-1_all.deb 4177fcd6cc59ae98b577720d9a74aef7d22f54fb 359042 tryton-server_4.0.4-1_all.deb Checksums-Sha256: 7b2323c6a4f753bc3c1d385c8ebcb88356eee219f3d7b7c435c773c953983cc7 2238 tryton-server_4.0.4-1.dsc a0b7ddf5c4530904865e2f7547f4d983d9147fb4c5c7b2514ba820d44f0f8ddb 602383 tryton-server_4.0.4.orig.tar.gz 6d1bb76cf092ebdf31459caee8a77ee53d5ac4eb77a094d5654101a970b28c78 39140 tryton-server_4.0.4-1.debian.tar.xz 559ed1c14c003c126792807631125527341dff7ccce5a2a9a1c8ba996162b25a 112488 tryton-server-doc_4.0.4-1_all.deb 5b66821ca4ab0c54c9ad29b97204e1eb9b13160fc5f35e82f198e38fd91fdf0b 359042 tryton-server_4.0.4-1_all.deb Files: 5c362a73fec0eab008ae4200330a05f6 2238 python optional tryton-server_4.0.4-1.dsc f365f693ab8072e42286f8f2e7898c87 602383 python optional tryton-server_4.0.4.orig.tar.gz e63af1657ac5d6f661a4a218bcfa30be 39140 python optional tryton-server_4.0.4-1.debian.tar.xz 6fd8ac27f7693d25a70de0b028f72d53 112488 doc optional tryton-server-doc_4.0.4-1_all.deb a476fa455e638a3212a8451056e2df43 359042 python optional tryton-server_4.0.4-1_all.deb -----BEGIN PGP SIGNATURE----- Comment: Signed by Mathias Behrle iQIcBAEBCgAGBQJXxYPyAAoJENbQm+SEBbv20RwP/3/mU4Bj85CYuxUztPDFGs/N Jg1eN02Kro8lJAKuEqlF6MaXwKiN+MFw7ph/sMQSEAZWFUnczJRm7rVZMuY3FdK7 GyY7hkadcCydOwE+531UjcMYbSakmCKC+BpxD3HBUU2Jt1MhfDs9H9CHyyUgaSmx bAuePYv0RrBAOLjt873sHkDSGo7laQaA/4124Y/9BVNiAAYf7QSLf6J9G8bHXdZc LJCTdg9izVg4fL7FezRl+7FSe1QpAZhqJU1ecJCaSd7fC5/0hYCz0/NMbhKy/xJu b0nKTLMi0d3dOaYpJGqGtoMVJjO+32j7Y4UViTW64SU/Zq7l2HgKWUfGw6ucf+fE NbkG9iY2t/QgDwYo3C9S45gDf4O/YqL/bh+ZC5BOKn/D6nNMVL6oAG54DW0G7s7k CehOxrAI9SMH+OSkUdt1/AqxDoYSQKi7HuTVfvw1whxUkgfhjBU/WSGbC8cDEUSv DMe96c7/ZmytTR+IyRcJXjj/uNhz6WufgXWrtvR1gQOvs0uG8+TF+CPtFv8i55bO F1fvP2nZCx05EDlegf6Y8JskBbjoygu/WL9NRjQFV3YLaUwmngCdkdMFlQ/FpOOn a9xHOWRl6nRqHpMxA4u01l9vsB7RdA8ZZC9ITPcp8lIJ5lJHL7gq6e/R7a2btva2 ZbdRsv8zB5/W7r5Cm6FL =qqQn -----END PGP SIGNATURE-----