-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Jan 2017 21:57:15 +0100 Source: ruby-archive-tar-minitar Binary: ruby-archive-tar-minitar Architecture: all source Version: 0.5.2-2+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Alexander Wirt <formorer@debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 853249 Description: ruby-archive-tar-minitar - Provides POSIX tarchive management from Ruby programs. Changes: ruby-archive-tar-minitar (0.5.2-2+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2016-10173: directory traversal vulnerability (Closes: #853249) Checksums-Sha1: 134f9f4df51b425f601b19173c2362cc888e72e7 2082 ruby-archive-tar-minitar_0.5.2-2+deb8u1.dsc c26a196933d0dea7da6e46d5ecb280f0cb34671a 20440 ruby-archive-tar-minitar_0.5.2.orig.tar.gz 9c2228f409198dac3e7f5885db31262838900456 2540 ruby-archive-tar-minitar_0.5.2-2+deb8u1.debian.tar.xz 4e78675a975d6b673fca81b8dd33757eb396d111 15646 ruby-archive-tar-minitar_0.5.2-2+deb8u1_all.deb Checksums-Sha256: bccfd232c91315f50b9c6ee42e8fb7da5234e7115c78f9ed663cfbcc759089d5 2082 ruby-archive-tar-minitar_0.5.2-2+deb8u1.dsc 841632a21cb6fafff3a8c9c25cd326941a0096e3e17b9b15005c850e3526d343 20440 ruby-archive-tar-minitar_0.5.2.orig.tar.gz 85973ee316942ea74094a4e1c77427984ef9b0ac8093aaae3872c6887dac524c 2540 ruby-archive-tar-minitar_0.5.2-2+deb8u1.debian.tar.xz 795df248fea4a7cf1b1e6f9c2f3692503a30c189af3c767f0a84fa240cdb7eb0 15646 ruby-archive-tar-minitar_0.5.2-2+deb8u1_all.deb Files: 5457c15b104479108210289a3049f49e 2082 ruby optional ruby-archive-tar-minitar_0.5.2-2+deb8u1.dsc e9187af86dbce33e67a29bc627c130ec 20440 ruby optional ruby-archive-tar-minitar_0.5.2.orig.tar.gz a38be9555abf9d9a5cc721eda2962e14 2540 ruby optional ruby-archive-tar-minitar_0.5.2-2+deb8u1.debian.tar.xz 463bde9a80076e8928942c9ef7b413d1 15646 ruby optional ruby-archive-tar-minitar_0.5.2-2+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAliPqXdfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89ETKwP/RLkq1ek2monR/Q/7bCwAXzka0Q0SxW7 3EmoPZtvn9pjoNWcsHGTdjG3Os33NgmoqE7MK1Cz2+8YC2dkNEXSzYPbjn0VwecQ 2xLeFkEmwTjs1kbRX/l3aohCzvTrs4zz7CEEjuEhEhSLcpAt8tRu9LhuG+63L+Y4 C6EHA4ygI3/UC/PyFmpb596W1g+HdKhvggm4WF/CovKafKfsFASnj7flqSnWOMJ5 uCw4BeiB3JQBHpXrqgJ8IeXTedZncRJx+nPr6gJsLA9iF5hWphelftS9/JrkDM2e oqv4KTY/xJuZqL4ROwPmBp43m9zkGC1V85e7EOHRWwDgiR0mA4hSs3Vhz1vznMAb Ol+sbECa/NGY7Ev1KxsiDtnfewAGDqHSDszvYcC+2ozIaN8T44cg14cQqDCeM6hq TrNQZV1Z93uBLU2kM+mtT4V/fEISEbIiLsnzffAo0h1JAGEj2/v+YRbQy3IINFoB xJBjNPhypVmFYOJBKg8EGo9AzPeltJOyYVz6xcjqKoNwh3exVTb7rIfD/QBRxXTR vHrKkQfIhfxLVPMIbdpvexwNe1toLG31w+im77n3PKLesI1cODuqcv4bU8knsj/E cbGSzizTZIS7ynhWPJxLB8VUJRYoPqbCdrMrfMBtACh/yCn/+t8KjdsDR8h6Wzs5 mm5F//6s2KQy =vW2D -----END PGP SIGNATURE-----