-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 07 Sep 2017 16:41:41 +0100 Source: unrar-free Binary: unrar-free Architecture: source amd64 Version: 1:0.0.1+cvs20071127-2+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Ying-Chun Liu (PaulLiu) <paulliu@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: unrar-free - Unarchiver for .rar files Closes: 874059 Changes: unrar-free (1:0.0.1+cvs20071127-2+deb7u1) wheezy-security; urgency=high . * CVE-2017-14120: Prevent a directory traversal vulnerability in RAR v2 archives where pathnames of the form "../[filename]" are unpacked into the parent directory. (Closes: #874059) - Add accompanying autopkgtests. Checksums-Sha1: ae40c1cc1e9267f0f19da4e195fb80e732d140ff 1916 unrar-free_0.0.1+cvs20071127-2+deb7u1.dsc 44440cc07f3747f65aa49198902c42caa423a8b6 127267 unrar-free_0.0.1+cvs20071127.orig.tar.gz c9a35b2b77672343e69066ba3115e396ba0ad7e7 7312 unrar-free_0.0.1+cvs20071127-2+deb7u1.debian.tar.gz 444244e190ce2dfb15e15979c90a2091024f16ed 26248 unrar-free_0.0.1+cvs20071127-2+deb7u1_amd64.deb Checksums-Sha256: 4724d93272f6ca505f242829ff3ab0588eadd60f102e210c3a9dc6e14e214cd4 1916 unrar-free_0.0.1+cvs20071127-2+deb7u1.dsc 9932cb1940305b76bab6351500f614d1355252ac326343ce0a8c5586b9eb8e1b 127267 unrar-free_0.0.1+cvs20071127.orig.tar.gz 6287cbc983abc1c7b8184f3dda7144ba37b1beb397cf31e0584b6ac0f0e12f9b 7312 unrar-free_0.0.1+cvs20071127-2+deb7u1.debian.tar.gz 6dbb0f5f9134ae5146edc5e149a892921349bcbd9dde9fc599d8c581990b5e34 26248 unrar-free_0.0.1+cvs20071127-2+deb7u1_amd64.deb Files: 496eca0cd3ad8011108b48e750b80a64 1916 utils optional unrar-free_0.0.1+cvs20071127-2+deb7u1.dsc 57656f5b5cf46894d07364bb365a50a7 127267 utils optional unrar-free_0.0.1+cvs20071127.orig.tar.gz f7906c2233b21bdfa2ff1a1ed22414f9 7312 utils optional unrar-free_0.0.1+cvs20071127-2+deb7u1.debian.tar.gz 67daae4e060febe323fae1652437599d 26248 utils optional unrar-free_0.0.1+cvs20071127-2+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlmxalQACgkQHpU+J9Qx HlgsFRAAockU6r9xh4KWNZGFPmP6T8F3MCXms6iWEjqJ3xF63LdrsxIA5GCqskd9 PKtk1jQSW5z+iEojfl/kMm03spBDOu28k+tpylLk+wXiGIvjGCwI8kT+MzzaDhIN FBYSmvHQtbUXbfiOj/bvSMvj8RyvfM+5vY0arPNbzZSG4ih9Hr8OhBGAM/FuhBwt yNn7y04I83Mfu5uYA0Bag9jK791dyIANCVfygwSeF4vQoFtZX3UBkI4oLV1F9rBM zvvuTxjRKeeBOmtCsdG/GkS4BW6skfTXabobSqVuclGhbkYsof+dKE0++ALHCfqh baYc2LQQPX6k97ubg3yPI1NTMlvQhvepoH4EaYoANIneDmwnGxlggirL2NpenW4W CSrO+p6a1rArdTmYYyLc4UdO5e0nI9CWnIdYts9TXcEnTIrrKqPI6HPZOc9tE1Qb s8oPewwvFYTmzua4DwMk48ym2dsFLD28rfzk9yb2pgY91jqxmLdojVsMNNLtn296 tAnm36In9xLjgkyuYiwALTGLgm+Gkht+GPjCu8paTGL4USDKPnfTSLbpJp8Bk9B8 fEeyRQdqspWMfhZ9V2BG3TeGFkSQRBY27pym0Qv58x4+jYgjYSJXF4PwIYegePhY zNXLFJufnlA8QRgHieGMe04MIFAqyV4IVmAgjGmnVzrTTkWjHmA= =98fB -----END PGP SIGNATURE-----