-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 20 Feb 2017 18:03:02 +0100 Source: bitlbee Binary: bitlbee bitlbee-libpurple bitlbee-common bitlbee-dev bitlbee-plugin-otr bitlbee-plugin-skype skyped Architecture: source all amd64 Version: 3.0.5-1.2+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Wilmer van der Gaast <wilmer@gaast.net> Changed-By: Thorsten Alteholz <debian@alteholz.de> Description: bitlbee - An IRC to other chat networks gateway (default version) bitlbee-common - An IRC to other chat networks gateway (common files/docs) bitlbee-dev - An IRC to other chat networks gateway (dev files) bitlbee-libpurple - An IRC to other chat networks gateway (using libpurple) bitlbee-plugin-otr - An IRC to other chat networks gateway (OTR plugin) bitlbee-plugin-skype - An IRC to other chat networks gateway (Skype plugin) skyped - Daemon to control Skype remotely Changes: bitlbee (3.0.5-1.2+deb7u1) wheezy-security; urgency=high . * Non-maintainer upload by the Wheezy LTS Team. * CVE-2017-5668 Fix for incomplete fix for "Null pointer dereference with file transfer request from unknown contacts". * CVE-2016-10189 Null pointer dereference with file transfer request from unknown contacts. * CVE-2016-10188 deactivate any incoming file transfer for bitlbee This affects any libpurple protocol when used through BitlBee. It does not affect other libpurple-based clients such as pidgin. Checksums-Sha1: d529f0a4c7150878343ced6571d4efe64d8ef2ab 2402 bitlbee_3.0.5-1.2+deb7u1.dsc 74afdff87be49ce060771a6ae10d7643cd57b9b6 727982 bitlbee_3.0.5.orig.tar.gz 953e04d83fb971d040d0e0a8bcfe4fe02efd5316 27436 bitlbee_3.0.5-1.2+deb7u1.diff.gz 498a84d6e7b3734f43b5f758fb044f551882eb09 136754 bitlbee-common_3.0.5-1.2+deb7u1_all.deb 356511d25e7b0497dca6180918ed0c07c67990b0 26182 bitlbee-dev_3.0.5-1.2+deb7u1_all.deb b18b2c126a96d86c72b8402fae56a6f6f3cf6162 287522 bitlbee_3.0.5-1.2+deb7u1_amd64.deb bd5c6bbe9cefde5272fcd67a6a50a4ca1f46df56 121890 bitlbee-libpurple_3.0.5-1.2+deb7u1_amd64.deb f32f338ee15cd8b30ef12cf96a88195233246ee6 17068 bitlbee-plugin-otr_3.0.5-1.2+deb7u1_amd64.deb Checksums-Sha256: 7adf31f2f83e9f5c106aa5db7059a18f5eb8200290591a21488392060954f2ad 2402 bitlbee_3.0.5-1.2+deb7u1.dsc a2b18ae0355650b7ec326b8ea7082eb06bb8f8816ad3b4985fe97f729ce84e59 727982 bitlbee_3.0.5.orig.tar.gz c45a08ee5b9570c24503db53f0c4d3a350f086069bc39c2956bbf49813f8a431 27436 bitlbee_3.0.5-1.2+deb7u1.diff.gz 7b1bd9c0ef546a20f4ddfc9355e88030131b07196fc9f87ce148f81806d752f0 136754 bitlbee-common_3.0.5-1.2+deb7u1_all.deb c8901cc712848980c2cb775b64a9436817057f1418d4ce367ce502c6d3cf286f 26182 bitlbee-dev_3.0.5-1.2+deb7u1_all.deb a94a0cbc9c3433c23ec560d6e1e188e167392ba87a1654c5bcca7f05e5c5cc0f 287522 bitlbee_3.0.5-1.2+deb7u1_amd64.deb 44b3498f184b7242eb32e47dc6370ba68aa0ad4b68adbf997a43a68b6e79ec8c 121890 bitlbee-libpurple_3.0.5-1.2+deb7u1_amd64.deb 4c8fcfe3284b8d896c12df5795e7f9e57ddaf2e4069d20162cba7936f78c2e0d 17068 bitlbee-plugin-otr_3.0.5-1.2+deb7u1_amd64.deb Files: 76fe3b940ea2f031b87a48c341e2abf9 2402 net optional bitlbee_3.0.5-1.2+deb7u1.dsc 9ff97260a2a7f3a7d102db158a8d9887 727982 net optional bitlbee_3.0.5.orig.tar.gz 233b2b34fd2b70535d0ff65d28a1e6bc 27436 net optional bitlbee_3.0.5-1.2+deb7u1.diff.gz 34e3bf729598745e0f9da37924f5797d 136754 net optional bitlbee-common_3.0.5-1.2+deb7u1_all.deb dffd75616fee26f9c86f89f836284d57 26182 net optional bitlbee-dev_3.0.5-1.2+deb7u1_all.deb 3ca285861388cc53305ce0d7b7e4fa57 287522 net optional bitlbee_3.0.5-1.2+deb7u1_amd64.deb abc5c2a456384f1ff28d16ce91e9cdf5 121890 net optional bitlbee-libpurple_3.0.5-1.2+deb7u1_amd64.deb 7e01152d4a772931e9e88b0b57eba90c 17068 net optional bitlbee-plugin-otr_3.0.5-1.2+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAlirN+hfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR5mfD/4nQgnTPkmrades//qY287diLEI0PKw CoA8bPd1S5V+8ZTEVcgS2ZUPIGKg658iAa7np0EbyEF97wNUF81f9cfe2T/n5RR1 /cVRnVyaiYJcGpAMtfsLuL0+RpHpugERQk1uRt1YEU3DMl38xnx3EqPN9DFRha4i lN9ZQvM0JyQym8SlQbuAbTmw/pI0HcvkiFsdrmgkHyBLmKlF12emRT7pQA9HA9NH mL5Se/eU/NyVj3gMDobOrTwx/aYtvj5rgJkO7d+utzOuDe26ApxhRsauBGWPOFWf JjhRM3T9EpSaKgK0d7YhtDx/ZcA1wISywoYmGu7VU1ec2sQXm3CMZWCIRG0sKvwh xqUfAMLr1f1gO2dEXP9N8q31/LsChgfoTKdqtMtndo/fg+91SPe50bMpJdX2rEQN eIHs0QzgdrX4nyV5Yt7H3ulg6cjgR3TjcOos9nQfPXavH9p2hRUYFpPWU/6p06tA +BCpEBA2tCGVj9rdzP4ejZvj9uC5CF3T+djW9K6C1nwqZiVhbzaymwsfxHK+orZs 7Qa62cRIfi9do1077zH5szwQmlO1Jzm3dJuCkZgvmh6oiGiSeI/dyDo1BrNm5WGs waq6ISFGdx1ML0Oxd+2K1RNna8yX6+sDqb+SHxA8D6YDG5nYH7DGi8QTJn+Q4OF9 hUbIJ5eCrCga2g== =T9p3 -----END PGP SIGNATURE-----