[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Installed slrn 0.9.7.2-6 (arm source)



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sat, 22 Sep 2001 11:23:35 -0400
Source: slrn
Binary: slrnpull slrn
Architecture: source arm
Version: 0.9.7.2-6
Distribution: unstable
Urgency: high
Maintainer: Joey Hess <joeyh@debian.org>
Changed-By: Joey Hess <joeyh@debian.org>
Description: 
 slrn       - threaded news reader (fast for slow links)
 slrnpull   - pulls a small newsfeed from an NNTP server
Changes: 
 slrn (0.9.7.2-6) unstable; urgency=HIGH
 .
   * Upstream security fix; slrn's internal uudecoder auto-executes any
     shell script in the archive (thinking it's a shar, presumably!). That
     just doesn't fly in today's internet. Slrn in unstable is actually
     probably not vulnerable, probably, since it is set up to use the
     uudeview library for decoding. However, this is too critical a security
     fix to omit.
Files: 
 329de1af9dccfc89f3ceada8428ad22d 315196 news optional slrn_0.9.7.2-6_arm.deb
 2048a327919b407db703c7601cdc7033 90104 news optional slrnpull_0.9.7.2-6_arm.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE7vys52tp5zXiKP0wRAsL+AJ4y6idwKEwHprQ12L/OMlB9JMFR7gCgh2NB
W+Z2mWsYjs5tDsGDQlys+J0=
=bk8w
-----END PGP SIGNATURE-----


Installed:
slrn_0.9.7.2-6_arm.deb
  to pool/main/s/slrn/slrn_0.9.7.2-6_arm.deb
slrnpull_0.9.7.2-6_arm.deb
  to pool/main/s/slrn/slrnpull_0.9.7.2-6_arm.deb



Reply to: