-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 04 Apr 2017 10:11:19 +0200 Source: tryton-server Binary: tryton-server Architecture: source all Version: 2.2.4-1+deb7u4 Distribution: wheezy-security Urgency: high Maintainer: Debian Tryton Maintainers <maintainers@debian.tryton.org> Changed-By: Chris Lamb <lamby@debian.org> Description: tryton-server - Tryton Application Platform (Server) Changes: tryton-server (2.2.4-1+deb7u4) wheezy-security; urgency=high . * CVE-2017-0360: Sanitize path in file_open against suffix injection attack. Checksums-Sha1: b98f4f9ff557d6598ad9d688c26cd878179ed16b 2075 tryton-server_2.2.4-1+deb7u4.dsc 218ce50b2255ec4886a6925f06283e7342be5e59 283376 tryton-server_2.2.4.orig.tar.xz 413a7b6d987c6fcaad2a85fa0c4e349dd205681c 18604 tryton-server_2.2.4-1+deb7u4.debian.tar.xz 69023f52383777c45c70f3a5aa6368fb556c2699 274106 tryton-server_2.2.4-1+deb7u4_all.deb Checksums-Sha256: 5b4663c34d2ba8fec95f74a69c138d6c477c8cc98d8f49a015e47622cf599bbf 2075 tryton-server_2.2.4-1+deb7u4.dsc 74d3db176788d054f06aaabf9d30f4fa8772329ac6d93bf046515040cf2c0251 283376 tryton-server_2.2.4.orig.tar.xz e6bb74c62d1f97148985fc2506a918a1617fa310119b0906717136102551b7e1 18604 tryton-server_2.2.4-1+deb7u4.debian.tar.xz fedc0485bc3e86ba9dd643bb41ee84bf9f8b78b76f35812f97286f46fc29e8e9 274106 tryton-server_2.2.4-1+deb7u4_all.deb Files: b5606e4c5ff9e46f99a1f58f1af66db0 2075 python optional tryton-server_2.2.4-1+deb7u4.dsc 690903b5f0b4c6706ca18ddb36e2f69d 283376 python optional tryton-server_2.2.4.orig.tar.xz 6f8b9c0eea1221ca0b1bc8b50bf58171 18604 python optional tryton-server_2.2.4-1+deb7u4.debian.tar.xz 98b6f20a73c137526a514277c93fa898 274106 python optional tryton-server_2.2.4-1+deb7u4_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAljjWCkACgkQHpU+J9Qx HlhPFg//Z/HtjuXOSkfUkeaOKWgQin3BCaiPkyjPA1jy+uqdSPo/c8HONz1tq6Qo n3UGE+/y0e6b/6sUnGn5pQSNLC2q8cPORaiNY7JwLLverl9KY5r7JEaY781dRmGd ZLXKyXuuPNq5Hbt2G8Q8xTHh2ClKYnmeYUHHfGRv0fJdvP4Bx87oSgvgLfxZbT6z 6RNJbf946spwZdYVik9aSPfP8W1uf6k9YQ+s6wY/SjbiiPNgBNe1aUIKXt5vrbEx qCgDThAs9ehI3v4B445GUefesoK6jKYUx4jCeyILweq53heEERw/4JoAkFVDkDou VCWlCTVFz+XHLbHSzuRh6cIaPw8NtwDUSQfbctGrvGqQyePvYvHhIddU6olbBr48 JGiw63KMZpunxJN9i7vL5l9/t73jhALhCJegJMjx3/5JR2N0uZ490Er5hpzrzO48 dhrJ5xMVQSK/GkO7eJj3iXnMBS3uG6ekm62unIoQ1XgiY2XhtF5DEiqlldaVdIn6 bG91rbCU0uvEzaWTBvAQ3uQkvaUx4IRJk5WGEcEjG5NPKgXUtoFJHdQZdw7HeUOo w9HAtQo7huOLXutOVc/f7OkzH0RaWMkJTOrA2FU8wp/NnVfAXl65ijTgXuOp859I S/iVlKbCguhjRXXDxP6gRuOU3L7O11JH/pUYMrvtRyVzHAxsAyc= =NhIw -----END PGP SIGNATURE-----