-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 27 Jun 2018 13:38:18 +0200 Source: php-horde-crypt Binary: php-horde-crypt Architecture: source all Version: 2.5.0-5+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Horde Maintainers <pkg-horde-hackers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: php-horde-crypt - ${phppear:summary} Closes: 859635 Changes: php-horde-crypt (2.5.0-5+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2017-7413 and CVE-2017-7414: It was discovered that in Horde-Crypt, a crytographic library and part of the PHP Horde framework, a command injection was possible when a Horde user used the PGP features to view an encrypted email. (Closes: #859635) Checksums-Sha1: 3bb67c3e52f69fff674f817124ef936e1bfbdae7 2261 php-horde-crypt_2.5.0-5+deb8u1.dsc 90296756c517d77c4f22824f875d97ce803183fd 147698 php-horde-crypt_2.5.0.orig.tar.gz 9590a1cdb55877f1a42f56cc49af4578b24755da 3312 php-horde-crypt_2.5.0-5+deb8u1.debian.tar.xz e2daa4ccaf6dfe565da7ce3dfbeeea7ad8ca23c5 108628 php-horde-crypt_2.5.0-5+deb8u1_all.deb Checksums-Sha256: bced306341ead0cdc4f16ece1b888e5132ec805255c40ce7c7f7b10e87bb9f2b 2261 php-horde-crypt_2.5.0-5+deb8u1.dsc c4278797164cc8334509d50f7720a335cecbcc0d6058d31f2ff47085165490ae 147698 php-horde-crypt_2.5.0.orig.tar.gz f3edf97af1afdfd025c46a73892886a113f8a84ff6df9f9a3d32aae00ce93302 3312 php-horde-crypt_2.5.0-5+deb8u1.debian.tar.xz e48a10b7ede0c53ee4ad48d4c69492081fc2c23f0e15b63ebb34c62cdb4a55bb 108628 php-horde-crypt_2.5.0-5+deb8u1_all.deb Files: 0ed81f849d8620d13b891e59d2593bd9 2261 php extra php-horde-crypt_2.5.0-5+deb8u1.dsc e0582e282a20acd566417b4b0b369eab 147698 php extra php-horde-crypt_2.5.0.orig.tar.gz 7144d7a7906ad2c3ce917ce8784ad5b2 3312 php extra php-horde-crypt_2.5.0-5+deb8u1.debian.tar.xz be33bda872b3a064808d9b5b009bfb2f 108628 php extra php-horde-crypt_2.5.0-5+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlsziCRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkbHMP/349LBT3UG/XLbX6LaeII2YgoQWCx1yz/fHp WNTvCu6tLHjrIfJSm3pdLrLPpSfp9d0xqCOSMdJfPMUUPjhaWwJ5I1TUv68yhVNh x9k0/afmOGd7/UQjT1qTOQWq5psbzitmVIeRq5fI1vPi3UTkeVq/RdLja/Z4HHyG 89JFsDnNLEZVCUCUEfYoz7+sYy9mgMnVH0EvJxAVO55gBNx2uvLw+R96iAJUS/SM FH/0s7putHZW8J9qLhJl6VwU/yN3RZ96kAYhbYY4j9dlkIUy9bGQ4jMw7eSRETws DjtWhNRKB44i3PGRuQ6ck6AjaMuCSBREZKtfSLwg6Gn6CesdMys7SkL5bXYtAmYM Bv2/GmNGA+nX0jWxHc4vpPJ+btQfEt+mjB9xTk7TYvgJ7OcdgAnXwshjYiIyNsVw oghpRczceLNA6qoHrbjDQvY0nulhhqlxKoQYF1uWPQ3mlm/Gp6LP19IkbBc5cGT9 /pCdBfBJDrq6PUx7eiJ/kysfCfvyDJj0zudmDJNXV7UiRx8mFxEZmc2ean6NK1XO ufdKjLr5KoM8YbiZGvEXKqjpb4+GnQrZeJ3kCbeA701/z+M9pPu/GTcG+MrMWFwx 4uQCS87jJFR6nyId4YxU7cvHbXw2CckRwd6yZBId8FvaI/10+PTL2YBBPsaXciHC Y1i9Krj5 =mY8Q -----END PGP SIGNATURE-----