-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 22 Nov 2008 16:04:04 +0000 Source: shadow Binary: login passwd Architecture: source i386 Version: 1:4.0.18.1-7+etch1 Distribution: stable-security Urgency: high Maintainer: Shadow package maintainers <pkg-shadow-devel@lists.alioth.debian.org> Changed-By: Nicolas FRANCOIS (Nekral) <nicolas.francois@centraliens.net> Description: login - system login tools passwd - change and administer password and group data Closes: 505271 Changes: shadow (1:4.0.18.1-7+etch1) stable-security; urgency=high . * The "Curé nantais" release * debian/patches/303_login_symlink_attack: Fix a race condition that could lead to gaining ownership or changing mode of arbitrary files. Closes: #505271 [CVE-2008-5394] Files: ec01ac54e482ea552fdae5753d6c1745 1406 admin required shadow_4.0.18.1-7+etch1.dsc 3f54eaa3a35e7c559f4def92e9957581 2354234 admin required shadow_4.0.18.1.orig.tar.gz b78d9d738765da65a6b55dea102569c3 297817 admin required shadow_4.0.18.1-7+etch1.diff.gz 82c630b2f4e18217170a73a2dab27cba 792460 admin required passwd_4.0.18.1-7+etch1_i386.deb 439cd50477db064cdf11d9b48c0e9af0 796578 admin required login_4.0.18.1-7+etch1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iQEVAwUBSW3rfWz0hbPcukPfAQIexQf/cUd2fZ9UooLPR830+AeYtPMC3p74736z kYcWf/SUegGntDtylsrzTw1GWRfi5TZV8kdgBA+CPxoY0JHJlWnaUFyqwQxUR+Ux os2crtjnjE/IT1n/+cUqLdVujwNk3LEX67W1Z1+RDcrPUTbyfRyRvTgUrLKVCZuP PaNCMHV2Z3pqjvDrIznkWfzpp0IPeMP37hTlr4sBt+QFm8JugGyxT0tiVatEFzMf UT9F10+Fpa6IrWHtdaSnpDlfTa31v4km07t1i/3OcobZVd/h3vsbIz+azBmlo/ar 59IfvmDhS6tM7WhFngCt/1tu50B0orFhiF8smRczhIuJx7iVy5nPeA== =+TJJ -----END PGP SIGNATURE----- Accepted: login_4.0.18.1-7+etch1_i386.deb to pool/main/s/shadow/login_4.0.18.1-7+etch1_i386.deb passwd_4.0.18.1-7+etch1_i386.deb to pool/main/s/shadow/passwd_4.0.18.1-7+etch1_i386.deb shadow_4.0.18.1-7+etch1.diff.gz to pool/main/s/shadow/shadow_4.0.18.1-7+etch1.diff.gz shadow_4.0.18.1-7+etch1.dsc to pool/main/s/shadow/shadow_4.0.18.1-7+etch1.dsc