-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 18 Jul 2017 20:52:29 +0200 Source: evince Binary: evince evince-dbg evince-gtk evince-common libevdocument3-4 libevview3-3 libevince-dev gir1.2-evince-3.0 Architecture: source all amd64 Version: 3.4.0-3.1+deb7u1 Distribution: wheezy-security Urgency: medium Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Emilio Pozuelo Monfort <pochu@debian.org> Description: evince - Document (PostScript, PDF) viewer evince-common - Document (PostScript, PDF) viewer - common files evince-dbg - Document (PostScript, PDF) viewer - debugging symbols evince-gtk - Document (PostScript, PDF) viewer (GTK+ version) gir1.2-evince-3.0 - GObject introspection data for the evince libraries libevdocument3-4 - Document (PostScript, PDF) rendering library libevince-dev - Document (PostScript, PDF) rendering library - development files libevview3-3 - Document (PostScript, PDF) rendering library - Gtk+ widgets Changes: evince (3.4.0-3.1+deb7u1) wheezy-security; urgency=medium . * Fix possible command injection vulnerability in CBT handler, this patch removes handling of the CBT file format completely and evince now requires unrar, unzip or 7z to open cbr, cbz or cb7 files (CVE-2017-1000083) Discovered by Felix Wilhelm from the Google Security Team. Checksums-Sha1: 8e90ddf570bcc4516ea4bff48a01bd3f26fee5ec 3074 evince_3.4.0-3.1+deb7u1.dsc 7159f4b1486fc07b5be93c3034965395d41c458a 6162936 evince_3.4.0.orig.tar.xz d13662ee0c6dce06e5e817668372a7ce88b2ae73 29054 evince_3.4.0-3.1+deb7u1.debian.tar.gz 9ba64f4fc8a18ca6531857002207dec21c72ee64 5155660 evince-common_3.4.0-3.1+deb7u1_all.deb 0bb1ae49853ba849917c54840b5ed6ad549d31a7 634934 evince_3.4.0-3.1+deb7u1_amd64.deb e8904ff05e97f7f02fa5146e994095936398ad23 1625244 evince-dbg_3.4.0-3.1+deb7u1_amd64.deb f4abd79d2d7271de78345f6d5a808da4475610bd 631674 evince-gtk_3.4.0-3.1+deb7u1_amd64.deb 859816e6040950b72d69322a76a2c55b8d7733c6 653948 libevdocument3-4_3.4.0-3.1+deb7u1_amd64.deb 7442bfd171a13fafeddca1ae8150aec3b91aac26 569036 libevview3-3_3.4.0-3.1+deb7u1_amd64.deb f3167ce4768900448cc5eb3f24e3f6d2c4e40004 713872 libevince-dev_3.4.0-3.1+deb7u1_amd64.deb 0b38a97c83a001553efecb8e98b85ff6a401ab60 499270 gir1.2-evince-3.0_3.4.0-3.1+deb7u1_amd64.deb Checksums-Sha256: 5f8a6481a579f1233b8f30788a2ce396ffa1f98069b3e3e1757c7be879ae28c2 3074 evince_3.4.0-3.1+deb7u1.dsc 02f1c74c123ea0cb4c1a98cb9ba2b67d724e9f90d7ff15acbcd6b8dbeef0a129 6162936 evince_3.4.0.orig.tar.xz 0cb2acd7dd8ba4fc37b3397b93bbb0a6bfd9825baf6bcaadfa56900a73bc50e6 29054 evince_3.4.0-3.1+deb7u1.debian.tar.gz 4432cfc477c28de46e5019c86f8dc6442ea4e7d7e3c49e2d1d1a7d1ffc1053a9 5155660 evince-common_3.4.0-3.1+deb7u1_all.deb ca6dd42af970ee59c3b2392d7cd6e680b5f0c6eb87f5afb086ac76078075a7ac 634934 evince_3.4.0-3.1+deb7u1_amd64.deb 95d8a84c3351856903aaf0fc72018c445198e05551c3ef9211feb19b1b367492 1625244 evince-dbg_3.4.0-3.1+deb7u1_amd64.deb c4ff4004a6751e0b4c18059919c81cafd15b35f8ddc5596a3a2c3840162bb92d 631674 evince-gtk_3.4.0-3.1+deb7u1_amd64.deb c23b185c4d03f2f04fbbc5252eb9e569bd172304066c69b73eaba027b4d27f6b 653948 libevdocument3-4_3.4.0-3.1+deb7u1_amd64.deb 551e143410af528f973321c7d8a02b039d3e8c1b8d32689b29c0841088da571f 569036 libevview3-3_3.4.0-3.1+deb7u1_amd64.deb ea3ae0421a02b5af5b3f9dfd7a9d078ff1d8ba23ab462405321e2c562c9f059c 713872 libevince-dev_3.4.0-3.1+deb7u1_amd64.deb 70655bd7c5955be657f9b2b4c26a1c1346b08867384ae546c731de9ea1f7832d 499270 gir1.2-evince-3.0_3.4.0-3.1+deb7u1_amd64.deb Files: 3b7f506ca3ace1039b82015cec08cee1 3074 gnome optional evince_3.4.0-3.1+deb7u1.dsc 23c8a5eec7686d2bb607f9c8245ad242 6162936 gnome optional evince_3.4.0.orig.tar.xz 560dd84179a77a834f77213566279e04 29054 gnome optional evince_3.4.0-3.1+deb7u1.debian.tar.gz 94b887808cb3e8fe19325171ef3cdd60 5155660 gnome optional evince-common_3.4.0-3.1+deb7u1_all.deb e1163e3038462704b2ef9f1fb515c205 634934 gnome optional evince_3.4.0-3.1+deb7u1_amd64.deb e682f20d9dfe1cb335d6a2880915371e 1625244 debug extra evince-dbg_3.4.0-3.1+deb7u1_amd64.deb 60570d5d933915c50b3ffffbae143358 631674 x11 optional evince-gtk_3.4.0-3.1+deb7u1_amd64.deb 3e0ef3a7c868cbf35a9c735a1fe2c3aa 653948 libs optional libevdocument3-4_3.4.0-3.1+deb7u1_amd64.deb be2f46b0097eb47ff2de29007e87b35e 569036 libs optional libevview3-3_3.4.0-3.1+deb7u1_amd64.deb 4469ef8b3f374206fecdbf9c9990ec72 713872 libdevel optional libevince-dev_3.4.0-3.1+deb7u1_amd64.deb 2701e5e96fe206583818c47268555802 499270 introspection optional gir1.2-evince-3.0_3.4.0-3.1+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAllucPsACgkQnUbEiOQ2 gwJf3hAAlys9iOx7i3QNGci5q5XNwCULwONP2rDkFyyReNAQSOydMQ9NJFCGrIqc HFWe7oiK2Y5ozjvDR/sQ5AUTyrYmrLGYVr0D8vg7tqlAMph20jfJISg6Wlx2V4tg aAklhJQicQoc+Teyn4GQrSu67Fs+6gaxLH7RqZItz5GkrNdap04IdhXpRhfBHWqK 8ZRGkIl6jnKYa6l8nXJ256TDhkmiC8jEEqhpG+oxHDXB4hX8skEq4bbX1Ag8CWwM /97B8dVi2WE4ltd9hhnYiTKT3VpeBqlKHT1s4x7hwWvDirL/BjP/lyHP9oKPisyf Z/sUsfiTNa0e4entny8Mx+HEsjAe/ZEFcEWcCxU0c1FiPwbxSXiyRuwY+HIHhefU fmq+Kjac2mpTxGXIKuDdHTn5dbEQra5hzPOuXUa3SudVpISK/bKS9AovdeoW3R8X sFvZGE30SVEkUYDWKshdvVhtciAcQhWe4KVKJy0ACUz1RK1Lm/bKkF/XoT8rxZ8E ybij5LKN6GqXmDXdVWezIHgsEjZYTcB4gpxLvEuePLTDzseQQTQ34kSrfNmqIeah AWGudAfu0+O1/h4JhjdbbpwGneI98YWc5fPzEC841ar+oM8FpElW5x2OGglzsGTw 2lrGLmXtVzuKav5enlRRuXSvlUAAWsGpp6Dyk9ETk830PgrujAk= =EKCK -----END PGP SIGNATURE-----