-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 21 Jan 2018 13:27:35 +0100 Source: openocd Binary: openocd Architecture: source amd64 Version: 0.5.0-1+deb7u1 Distribution: wheezy-security Urgency: high Maintainer: Uwe Hermann <uwe@debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: openocd - Open on-chip JTAG debug solution for ARM and MIPS systems Changes: openocd (0.5.0-1+deb7u1) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2018-5704: OpenOCD does not block attempts to use HTTP POST for sending data to localhost, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site. * Export CCACHE=none and add fix-ftbfs.patch to prevent a build failure in the jimtcl submodule. Checksums-Sha1: afdab23d7dc1889df5cb8236e68396fd2caa0efa 2162 openocd_0.5.0-1+deb7u1.dsc 807e4214b005029dccd1ed8af36f3897a5c6f49b 2228655 openocd_0.5.0.orig.tar.bz2 c0a00792fa7fc50b42e07b3221ded4d35c7132e8 409908 openocd_0.5.0-1+deb7u1.debian.tar.xz f8aec12e129212408c35ebe1980dac81c1e855e1 2722764 openocd_0.5.0-1+deb7u1_amd64.deb Checksums-Sha256: ad8cac54385c832eb88ac5e2a336b26d7335d5f5e224442a8054100523a614cf 2162 openocd_0.5.0-1+deb7u1.dsc 0bc122f98a6cd68c4392f6265d480b0e875ff54203ec05a5a52d23900903a78d 2228655 openocd_0.5.0.orig.tar.bz2 0e054813abac744b76ff49be6ad4cb3b76914daf79040c4e32d287da13d9f53a 409908 openocd_0.5.0-1+deb7u1.debian.tar.xz 8982b94830444394526b5b8e1988d2a50bb5752dca75bd0347d992c8f73cadd6 2722764 openocd_0.5.0-1+deb7u1_amd64.deb Files: 3c5f1c5fd679670b560359b373b22408 2162 embedded extra openocd_0.5.0-1+deb7u1.dsc 43434c2b5353c9b853278b8bff22cb1a 2228655 embedded extra openocd_0.5.0.orig.tar.bz2 3819f66c2637c821960f9795aa70c438 409908 embedded extra openocd_0.5.0-1+deb7u1.debian.tar.xz 2d4460a1734732d7abbeed25379c70f6 2722764 embedded extra openocd_0.5.0-1+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlpk3nNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkwdcP/2wsYCI0NZ7OA8Bj2dJo7YvkiuGit9Z+zTgY BQdWgd5hD1Nq8G8KeJtBbACKfsUIOe2nlXi0hGST0RTbL4fKn2q03RTKpVUQCBuG bQIhE+VU1ck9lOlFV/+/PUcjuJWDgb01vr/YV7ouZl02v99CkG4i4DF5O7Tj3umm i+M3MNbk98pH6vrNxAm+Y+Nupp1/vbi8cayp0aLYhNZfGLtFeQRQwXuWN4awg0er pWWlkOxKeD3FwwTusmMqjB7Puqd4gPWinZtWIGpE9kuEDS7mAuaI8n5oejKJfnsY z1OGgMQxKzicKE7CxA5m0+i8WGSjdhed4kG6BRaWHlV/mm7f08jNzxCY+THuuhGy O03H2UWtGffVk5k/YSSFVL5yKhaVy42TQy40NMN9rZV1l6WeA2Pgo/oRmey3TxJ+ oI8luKLn7hJazUraJ7Mlg3RyCVP9Cr2yRzfL0H6FNEEJ4TkLWJ8CGGpJhtxPEmhZ l+dp/L2PwXP0O18UWp/cHmfgsYBHJC28MVDKhZWav2XxJg5rYPCNm6TniQ+ZpInb sEbWLbmVtgNWfw5rpxZwComf6g1M9Qw1lB6IYFXPmHno0xJprMQTVUwkT0mnO5mg PMyw88wgDwL5r3Iv6Tub+0WBZLkEgPIzyodUCN77cfAR/XejsPdpc1XyoMfsaaOP IDhi0GOw =csNX -----END PGP SIGNATURE-----