-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 23 Jan 2018 14:25:04 +0100 Source: gcab Binary: gcab libgcab-1.0-0 libgcab-dev libgcab-doc gir1.2-gcab-1.0 Architecture: source Version: 0.7-7 Distribution: unstable Urgency: high Maintainer: Stephen Kitt <skitt@debian.org> Changed-By: Stephen Kitt <skitt@debian.org> Description: gcab - Microsoft Cabinet file manipulation tool gir1.2-gcab-1.0 - Microsoft Cabinet file manipulation library - gir bindings libgcab-1.0-0 - Microsoft Cabinet file manipulation library libgcab-dev - Microsoft Cabinet file manipulation library - development files libgcab-doc - Microsoft Cabinet file manipulation library - documentation Closes: 881922 887776 Changes: gcab (0.7-7) unstable; urgency=high . * Switch to debhelper compatibility level 11. * Apply upstream fix for CVE-2018-5345. Closes: #887776. This also fixes the out-of-bounds read in cdata_finish(). Closes: #881922. * Standards-Version 4.1.3, no change required. Checksums-Sha1: c0ac058a9dd5a3bfb7ec1549f8f8dd91e6f6c06b 2133 gcab_0.7-7.dsc ddc184d999c04c0320d62db925f0df3d442a14f7 10776 gcab_0.7-7.debian.tar.xz 78f2b07d70a3a2a39fe3da99c5a07d525db045f1 9275 gcab_0.7-7_source.buildinfo Checksums-Sha256: 35c1c8799fb32718cd2c5cfb025324756e45a23dfde4bacb137380f9a14bb6cb 2133 gcab_0.7-7.dsc b8253782bbd49a2c81cab49ad71acae733fec91a8ccf9990b03e2abe38112da0 10776 gcab_0.7-7.debian.tar.xz d1c7e0f6054ae98b5d78f8aefcdb4a856348aca25e578ceee51fe971ab6ae89a 9275 gcab_0.7-7_source.buildinfo Files: 385a13227e8f4b5d68f780643aa9d80e 2133 utils optional gcab_0.7-7.dsc 98875c973dd3242feedc6e291267d698 10776 utils optional gcab_0.7-7.debian.tar.xz 58820aa06fe0ce0bb387da8d959acc9d 9275 utils optional gcab_0.7-7_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnPVX/hPLkMoq7x0ggNMC9Yhtg5wFAlpnN9wACgkQgNMC9Yht g5xlaRAAkxv/iicLXynoLrQD5a2k/Iqc8yT+vN91FKY7J+6JW4v7S6DhfoIRP1fK 1IzOQgl2qG/g4z0m1CctULfe0JyYHZuQT1Y9F0oV66OqSvRSch1aoGcgSaASyW7T +34EW3t6cXD3nU75PrnB/tIAqquxZMTqTlMgm9E+LK+LTwNoq+HlXqyvZd4LP/Hz XvKoYvTkZI0igqRs+Vp+nqke+1Ajsu8UwH5c7/v3FPPfEuQuFF76yE7WRI06xXcm Es3MTMQHKqEaVshzINYwtY5M/b0WgNKKsrde/UUOYEJ6R7si4ijz1O2kmOoLEdbK hpNTB/d0HG9w2b7y6Vjn3nOmBx8KRtLwX4uVNjtdIiqiDYl27ogXQkEeoVWlgF5O U5lV+PPVQ/zKTKiXzTWZoqjLvnxWAfcPV99mhFGxMHrNCtQrjzyFOj1WF40ycYY+ JYgtFRked8zzBWv/Ia2V7B5e5nQ1UMgtdzV4CL+rvssVZyJz3XUQNqFynaYOvhed 7mbiFT537ygGOpR2juMCaCbVBnVKSJdfF9qaXsdO5DioB/bB9jI+zHmLBw9EripF 5xvvs4j5KwAwaenx2Ygz0UkJLlU0rALkPjOOINudMJTNNx2WrDT3aBwhbGa/2F1W wLR3urWiQ5w1mRt7OJ9QNob9p/RPCcrKIwACB3SYZRb8gf0UFbs= =/A6R -----END PGP SIGNATURE-----