Accepted golang-yaml.v2 2.2.2-1+deb10u1 (source) into oldoldstable
- To: debian-lts-changes@lists.debian.org, dispatch@tracker.debian.org
- Subject: Accepted golang-yaml.v2 2.2.2-1+deb10u1 (source) into oldoldstable
- From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
- Date: Wed, 05 Jul 2023 20:50:21 +0000
- Debian: DAK
- Debian-architecture: source
- Debian-archive-action: accept
- Debian-changes: golang-yaml.v2_2.2.2-1+deb10u1_source.changes
- Debian-source: golang-yaml.v2
- Debian-suite: oldoldstable
- Debian-version: 2.2.2-1+deb10u1
- Dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ftp-master.debian.org; s=smtpauto.seger; h=Date:Message-Id: Content-Transfer-Encoding:Content-Type:Subject:MIME-Version:To:Reply-To:From: Cc:Content-ID:Content-Description:In-Reply-To:References; bh=BxPhQl3YMWsTk8iOqnb5dI8UQipD4IJiCo11Mdx6pWY=; b=VC/sQKNqs0SOAvRjOIfv+BTmsk NPpXWj/+iHpWH/NEe9q24+3p9iJYllUue2+wrjOZsQfjUpBdkUCMxrfxjOeAXHCYgFOnOjuzZwQkN AIuXanqgSApcZlqV+OHwQowh7R7xCSqd6JHu7Fs74j+hdpbhxa/Vhyl6DhJMfOySuNOuE4mOf8fNL aMbWc7UP0N+0030/MQLF1n4Lc2h+2ZXbScx9RN6l/Ay26SZwvPr7SJz3JyQh9Qdt6Xtm8XyhEG8Sk Q5tDzvJSJy3x+haIVoiQZRE+iFVah1AdLom82ODGgQ2H3Mfl7xvQ3Siwr2C3U7wq+uPlJ+j89CYnk EJHLXzrQ==;
- Mail-followup-to: debian-lts@lists.debian.org
- Message-id: <E1qH9S9-00AUUv-9X@seger.debian.org>
- Reply-to: debian-lts@lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 05 Jul 2023 16:02:33 -0400
Source: golang-yaml.v2
Architecture: source
Version: 2.2.2-1+deb10u1
Distribution: buster-security
Urgency: medium
Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org>
Changed-By: Roberto C. Sánchez <roberto@debian.org>
Changes:
golang-yaml.v2 (2.2.2-1+deb10u1) buster-security; urgency=medium
.
[ Roberto C. Sánchez ]
* Non-maintainer upload by the LTS team.
.
[ Scarlett Moore ]
* Add patch to add logic to catch cases of alias abuse.
(Fixes: CVE-2021-4235)
* Add patch to improve heuristics preventing CPU/memory abuse.
(Fixes: CVE-2022-3064)
Checksums-Sha1:
e269d58df8988a70d54e82ebab3c8a81494c0d00 2301 golang-yaml.v2_2.2.2-1+deb10u1.dsc
153ef6d5479c73c30052f2a9c6877be66812d48a 70656 golang-yaml.v2_2.2.2.orig.tar.gz
2d28f195152e3fff8a6972c78a70d9250b4c0bad 7432 golang-yaml.v2_2.2.2-1+deb10u1.debian.tar.xz
4604fc4abc78c1128400c52ac6450bbb3cda785b 6026 golang-yaml.v2_2.2.2-1+deb10u1_amd64.buildinfo
Checksums-Sha256:
c2b2c6d7d0e12cf8fc7a501443e2a5ae23c76f7d809d0105c3a4762e914f88a1 2301 golang-yaml.v2_2.2.2-1+deb10u1.dsc
42c3e4ef9eca2860d22b3c6c5582c6c13fb4b417e5ebc1acc56ee5e2c4ddcaff 70656 golang-yaml.v2_2.2.2.orig.tar.gz
820fe7e47791d1971797e76e589b02b2989ad8227838b0a6bbb8905e60572ead 7432 golang-yaml.v2_2.2.2-1+deb10u1.debian.tar.xz
767e1df6a944b41f47bbb6d132dbde65e27eb2cc1147353a7fc16c99151f9211 6026 golang-yaml.v2_2.2.2-1+deb10u1_amd64.buildinfo
Files:
650e2bb5c228b0241d1011eacc9075c5 2301 devel optional golang-yaml.v2_2.2.2-1+deb10u1.dsc
d6f6163b289957b4fcab6d2e70756090 70656 devel optional golang-yaml.v2_2.2.2.orig.tar.gz
b0c10258cf448cfef9eb491b9341d5d4 7432 devel optional golang-yaml.v2_2.2.2-1+deb10u1.debian.tar.xz
a539b88e01f4de8ed249c435a2b0dfb8 6026 devel optional golang-yaml.v2_2.2.2-1+deb10u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEIYZ1DR4ae5UL01q7ldFmTdL1kUIFAmSl1wYACgkQldFmTdL1
kUIZoA/9Fe4Vk/mPI10V+5xewyeKUNT5sjUtsopj/tQQyddttfZEJQTa7oDNoDTa
oNj3wL8o+TESZn1HmkCWtFPXSB9/AQ/ylbuFXjh2/oggZF0BHZv74MyEkuFrv4+9
6ZnWXgfbOlMzvmT2IXF9+hH1cLB0njkGyPYCrr9pOy+2iDzVG0+/zjAQnm74NGsj
uoNAUOaC0LeELbE5m4iUVe0/VQPzHZmh5QIh6gd9YLGOfJtv8nBPjEqk+yDslrvQ
KyORO8p5uMYDJZk9y2TIHrv9m0veU4H+6+HP7c9R/0KzuwVLVl+gMGaM2qA6NdI0
WFg0Pn0BN2sBhUbSPLC14c7XqQKr2x/mL0bbiED2fpwaySWtZErXHWZ63CyNQq+s
8MEQnOvySZN4/nYSNrSmc2qy6dxFkbt+nU7Re998Cl7LiThw+SSARoMoX/nTE8sD
zYrxsrp2qrpnrSpMnmp4h2TE8f1eKfbIjLFS/gRouS5qOqza+egSht7R+duo386S
Gks4nRiIT7Ije/+TarR4DNgCvV9dk0D0aHF2uIxcR4/toaWcaHM9b3nvp2SAXr5S
Np2scHYZNcVvF64ktK2l9yGqTgjIsn5rMJdsR1nhiKYbnk4d30K4ifYcqkIsbE6D
0Xo91u+yFEqJKrEjPvL9dYbCGOWZp5GPTeAIRlbojH/SpC9Nids=
=sYwW
-----END PGP SIGNATURE-----