-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 12 Aug 2018 11:51:32 +0200 Source: confuse Binary: libconfuse2 libconfuse-common libconfuse-dev libconfuse-doc Architecture: source Version: 3.2.1+dfsg-5 Distribution: unstable Urgency: high Maintainer: Aurelien Jarno <aurel32@debian.org> Changed-By: Aurelien Jarno <aurel32@debian.org> Description: libconfuse-common - Common files for libConfuse libconfuse-dev - Development files for libConfuse libconfuse-doc - Documentation for libConfuse libconfuse2 - Library for parsing configuration files Closes: 904159 Changes: confuse (3.2.1+dfsg-5) unstable; urgency=high . * Add debian/patches/CVE-2018-14447.patch from upstream to fix an out of bound read in trim_whitespace (CVE-2018-14447). Closes: #904159. * Set the urgency to high due to the security issue. * Bumped Standards-Version to 4.2.0 (no changes). Checksums-Sha1: a1eceecd7b32861da6831748814f9e33f0716af9 2003 confuse_3.2.1+dfsg-5.dsc 68666ec3426821fed5d82c443136bee84b2b8b80 4896 confuse_3.2.1+dfsg-5.debian.tar.xz ca8c949f88beddbb1f4c3f3f6b90b16b644d8b77 5193 confuse_3.2.1+dfsg-5_source.buildinfo Checksums-Sha256: 197019c3a7cd53fcb914be92fe4caffb128eb2ccab3b3150abc4b99eaf4fb3dd 2003 confuse_3.2.1+dfsg-5.dsc 8b5b0192bbbe775f5e92bc618ad455674c519102d7ad6135f3a0e1ef7a796f1b 4896 confuse_3.2.1+dfsg-5.debian.tar.xz 4d64d33a73136f9b64992bd9cbb14b2c92801aa8004bb5ebcf5cc870ba0f5ffb 5193 confuse_3.2.1+dfsg-5_source.buildinfo Files: b37541dbc262b5315c47f469cc98f323 2003 libs optional confuse_3.2.1+dfsg-5.dsc deee6474346c2c7cbe2b2449f32138ae 4896 libs optional confuse_3.2.1+dfsg-5.debian.tar.xz d62a08da21a221e3defda58cd5df9bf7 5193 libs optional confuse_3.2.1+dfsg-5_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAltwAzwACgkQE4jA+Jno M2vgBw/+KJqSPUxrPcMMbYc1tq/snbQ72NwM4Y0G7ZeqzRAkiUfxhX4k0CWA1ZVp FYk/ytDm46JanyTCb4c8mx7hsrArIOPl9PkuFj/LJfQds6lwmSNXH5YsB9xtd+pk i5Zup2l8Lb8Tofk5NjKtR42KXda2bpB/yIte5RI1AvxNxPyx4w2daztabLjLYuqI 78Zv3vzqkgh+RAodPFWDEnwUE8e0zFAM+x9l3PICAkafL8t+Fd0eJG0y/rISR6+k ijLvOVvLwyjugAZrJ0iU3RO2l7juMawQt6J+v0YY8oOgcy28E48cLmrL9Oz+6/aA EB6C3j2KrLgW7rrkCnDWzsbadS0QZSseTeiNdiP0Q0Jn0R8ggsKpw3Was98qvCAp /hGOtcWMfwJrBcij5xJXBRSI7BCp4T/0t5DDAEBKkS2lrg3dQQMk5E2JuBm+MMYz ZOBjC5l7TCp/VDmEczZlcsSKmfGfPOUOju2BdcOgSRYJzjVHktiOE3GFd1uHAUmp l6lnVmzGu3uI87YDKs9VAyFGWdBiYqZG5BmHf/0vTpu++V7tlBPpCmVC21v4O8uN qEsW5Wt334TZicVaJ06BvJ80DY2TietHNeKBcuCrg9QWOBsG2GhssetBxEUPdexf 396lOyOCZnadQDhZ3MrE/fopCO4n9SXrWTQkbb71F4AwjLHf4PM= =8yYG -----END PGP SIGNATURE-----