-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 17 Jun 2017 21:31:56 +0000 Source: expat Binary: lib64expat1-dev lib64expat1 libexpat1-dev libexpat1 libexpat1-udeb expat Architecture: source amd64 Version: 2.2.0-2+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org> Description: expat - XML parsing C library - example application lib64expat1 - XML parsing C library - runtime library (64bit) lib64expat1-dev - XML parsing C library - development kit (64bit) libexpat1 - XML parsing C library - runtime library libexpat1-dev - XML parsing C library - development kit libexpat1-udeb - XML parsing C library - runtime library (udeb) Changes: expat (2.2.0-2+deb9u1) stretch-security; urgency=high . * Replace the Mozilla CVE-2016-9063 fix with the more complete, upstream one. * Fix CVE-2017-9233: external entity infinite loop DoS. Checksums-Sha1: afeac137e583f7b57d2289150b1b36a70d3c39fd 2295 expat_2.2.0-2+deb9u1.dsc 8453bc52324be4c796fd38742ec48470eef358b3 414352 expat_2.2.0.orig.tar.bz2 0baf1b767d271bc01928e7265728888c49764024 11448 expat_2.2.0-2+deb9u1.debian.tar.xz 87926920150607f95f56b4aade0378b11af4c53f 23120 expat-dbgsym_2.2.0-2+deb9u1_amd64.deb 27ae905cb2b4b8cf95b384609d03107795a9caf9 7305 expat_2.2.0-2+deb9u1_amd64.buildinfo 5bdce0f66664121a0e7bcdc7b94f3392fe0c6913 25990 expat_2.2.0-2+deb9u1_amd64.deb 304464a018274fc5f7b78dc23ff88267765e21ee 208226 libexpat1-dbgsym_2.2.0-2+deb9u1_amd64.deb c3d468f92e50d6bfa0a1760ee057116b9230e03d 133956 libexpat1-dev_2.2.0-2+deb9u1_amd64.deb 10ddcecd2075f4c7e55aedfe9cf160fa64fb2985 53668 libexpat1-udeb_2.2.0-2+deb9u1_amd64.udeb 3ce6299bdf2b3c8c4709bdcb20cd394f995e85ae 83402 libexpat1_2.2.0-2+deb9u1_amd64.deb Checksums-Sha256: 6d7f96d7148dda2857772b499cbe17d0feb1c016dcf35b1a6da7c846123bd20b 2295 expat_2.2.0-2+deb9u1.dsc d9e50ff2d19b3538bd2127902a89987474e1a4db8e43a66a4d1a712ab9a504ff 414352 expat_2.2.0.orig.tar.bz2 d3e171fc4d2e6173945daab7d7df46d640fa23134c9474080f6d1b65d494b0a5 11448 expat_2.2.0-2+deb9u1.debian.tar.xz b838a41da7d16d4e08d70b03810a28bacbf361614c91b12662fe7e01b359a070 23120 expat-dbgsym_2.2.0-2+deb9u1_amd64.deb 0f7d41a8953afdccb68543c53dcd8464f0603688944fdea6811bd926353c21ae 7305 expat_2.2.0-2+deb9u1_amd64.buildinfo b0f0929e96af77fd1c62d1b59b85dd4e8b2bdb38be95334b008936ce1bbc2a02 25990 expat_2.2.0-2+deb9u1_amd64.deb f279fa44e809fcb93815330a03e32faecbec6fb732543d5291eec85b207ded6c 208226 libexpat1-dbgsym_2.2.0-2+deb9u1_amd64.deb 51feb417cb98765121e99c4367df57053e7786b0238e3b4aca893a28330e292a 133956 libexpat1-dev_2.2.0-2+deb9u1_amd64.deb ce5b0754a17c3a43ad91b3b3edc3368bd42e1404b5a18aace050de31cdb9a2c4 53668 libexpat1-udeb_2.2.0-2+deb9u1_amd64.udeb 9275558361d2fdbb6e3caa10afd34b93253889b5e4d4e40af8ff4b0d42287b32 83402 libexpat1_2.2.0-2+deb9u1_amd64.deb Files: af9de44d3496b52bf16796bf79e884eb 2295 text optional expat_2.2.0-2+deb9u1.dsc 2f47841c829facb346eb6e3fab5212e2 414352 text optional expat_2.2.0.orig.tar.bz2 b1691bad32efeff7e2ef4c33cb9a22d1 11448 text optional expat_2.2.0-2+deb9u1.debian.tar.xz fb4b841e5d5686c9f30e829b39b49e94 23120 debug extra expat-dbgsym_2.2.0-2+deb9u1_amd64.deb 17a0c8cb395d048ec47b5cc6a005c6c6 7305 text optional expat_2.2.0-2+deb9u1_amd64.buildinfo 720ebe9f2a740b8e46f9aa2af26ffe26 25990 text optional expat_2.2.0-2+deb9u1_amd64.deb 9d01c9aab04542d88b2392f10acc29fd 208226 debug extra libexpat1-dbgsym_2.2.0-2+deb9u1_amd64.deb acce2d178bbf98e48faaaadc3621d406 133956 libdevel optional libexpat1-dev_2.2.0-2+deb9u1_amd64.deb 36dc630de01246fd05ccbe1eaae13a1b 53668 debian-installer extra libexpat1-udeb_2.2.0-2+deb9u1_amd64.udeb ea76d337138f0ee552cf88e075854c08 83402 libs optional libexpat1_2.2.0-2+deb9u1_amd64.deb Package-Type: udeb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAllMDXUACgkQ3OMQ54ZM yL8jbRAAivpBtMfKlBc+we47E1qQKqYgIBZHeOaUGzIZqBoinR7rcj11VqagXUl2 X9uFIWX//cuuX1c8q05c3X2yUDA2qnKYAa27OTW79Z7PBLiKRLSq8Wcuqd97gswf zvouQTUf8nAusA+c4ZUCwgHupK0gGhx8OrVj+efMQJH4Q9eYslj1SU7yi3XJeFOe ybnyzNtAQkw1+LoQOB6FMzjLyXFW1dTvDmhMEFgr938/WWY+FeoR9/HiohERkxZH 6VgZ6Oly7HK4NBKx+zqWDVvYWXJIrpvQtJZat4KiL8YYlZ3cGGlYCvUdno2HFEj4 +nt8xXnhalTp5YA9xraSpHewmrUd/1ddNKJPWXgeXSrDuMl9BX14ClVA1VXQ2X7z WGmG30Xb00+nMPbGw+1qQem/a45ehkL9CcKLPx2VX3cPS7zAYcq5fHDBjWfDVswf pv6mMsdLA9/3Iahe1EkM4BkW6xZaBHzUJAloQvDzRpHoOxYL9LE36X0uiTHDGh3w wJEiyWwhd2Frlfb+IAtaZBHLnQKDQ3ORcwI++ZWHxR5r7gTlzPvNly17jrD71UVX mbWn4HOV01tPOuoY0rJJCfL8I+HfZj+J9wOP/qVKz84vzKMuH1BdBEOxMoecDBqa 2usre6rJbtA1XL5nAwv+r5RJaOZjG0X9zgeT6ntf9kAsjohYo+0= =hifw -----END PGP SIGNATURE-----