Installed slrn 0.9.7.2-6 (arm source)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 22 Sep 2001 11:23:35 -0400
Source: slrn
Binary: slrnpull slrn
Architecture: source arm
Version: 0.9.7.2-6
Distribution: unstable
Urgency: high
Maintainer: Joey Hess <joeyh@debian.org>
Changed-By: Joey Hess <joeyh@debian.org>
Description:
slrn - threaded news reader (fast for slow links)
slrnpull - pulls a small newsfeed from an NNTP server
Changes:
slrn (0.9.7.2-6) unstable; urgency=HIGH
.
* Upstream security fix; slrn's internal uudecoder auto-executes any
shell script in the archive (thinking it's a shar, presumably!). That
just doesn't fly in today's internet. Slrn in unstable is actually
probably not vulnerable, probably, since it is set up to use the
uudeview library for decoding. However, this is too critical a security
fix to omit.
Files:
329de1af9dccfc89f3ceada8428ad22d 315196 news optional slrn_0.9.7.2-6_arm.deb
2048a327919b407db703c7601cdc7033 90104 news optional slrnpull_0.9.7.2-6_arm.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org
iD8DBQE7vys52tp5zXiKP0wRAsL+AJ4y6idwKEwHprQ12L/OMlB9JMFR7gCgh2NB
W+Z2mWsYjs5tDsGDQlys+J0=
=bk8w
-----END PGP SIGNATURE-----
Installed:
slrn_0.9.7.2-6_arm.deb
to pool/main/s/slrn/slrn_0.9.7.2-6_arm.deb
slrnpull_0.9.7.2-6_arm.deb
to pool/main/s/slrn/slrnpull_0.9.7.2-6_arm.deb
Reply to: