Accepted libarchive-zip-perl 1.62-1 (source) into unstable
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 20 Aug 2018 08:03:09 +0200
Source: libarchive-zip-perl
Binary: libarchive-zip-perl
Architecture: source
Version: 1.62-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 902882
Description:
libarchive-zip-perl - Perl module for manipulation of ZIP archives
Changes:
libarchive-zip-perl (1.62-1) unstable; urgency=medium
.
[ Damyan Ivanov ]
* declare conformance with Policy 4.1.3 (no changes needed)
.
[ Salvatore Bonaccorso ]
* Update Vcs-* headers for switch to salsa.debian.org
* Import upstream version 1.61 and 1.62
+ Prevent from traversing symlinks and parent directories when
extracting (CVE-2018-10860) (Closes: #902882)
* Bump Debhelper compat level to 10
* Update copyright years for debian/* packaging files
* Declare compliance with Debian policy 4.2.0
Checksums-Sha1:
d78bde73bb8e318fa9596825f6b51b2b5398e641 2355 libarchive-zip-perl_1.62-1.dsc
08842c4fd86d277c01ba0e16dbe14f0bd52511ca 191576 libarchive-zip-perl_1.62.orig.tar.gz
6ebc4645d63bd015106da86602f3debd89e331b4 8384 libarchive-zip-perl_1.62-1.debian.tar.xz
Checksums-Sha256:
bce56c5ba20bdda3c79b1c0183bc277f25a9bc3265c0e18600af4c57544355c5 2355 libarchive-zip-perl_1.62-1.dsc
2bf362586744cab99ccd7831ed294885e7a0f7d4cc557fa6c9a5dac3c7095dc9 191576 libarchive-zip-perl_1.62.orig.tar.gz
97cbb4e9393a4d23247956ff7cef55ee46787a95e9ab3aa073cd35f320b88d22 8384 libarchive-zip-perl_1.62-1.debian.tar.xz
Files:
619bb959945efcbed3865673f574ce78 2355 perl optional libarchive-zip-perl_1.62-1.dsc
af9eff34f8c948656e09c2ed348a675f 191576 perl optional libarchive-zip-perl_1.62.orig.tar.gz
992202b4b13656fdeadf8d0f3c88393d 8384 perl optional libarchive-zip-perl_1.62-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlt6ZSxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89El4AP/iTmfqD22fI8/aSq46R0Y/gfePuiwwn5
UcM5kWF70G+/H640sFeAKE1VpPeXOt1504iZGXXhPqujSTEQODdeFSA1LkSXfvZH
fWU48JeFOPCmFZko/YSBIAUd8UbHni/bBa4A+cM+xjrh2RUKLnbovApbKRq7U11J
W96m3CNhk2iklez1JaK+Sfhkqv42zL6YnO6FSMOjZv4wdKf5kaAI0a4X8g8W1Tyl
sGf3o0HSKVRC6RYarHMwMKCdN1JFah30vnEzqykMpnSX1zIb0811J7BHyZ4CjUdl
GncnbK5tJ4uxtWntgRFTeNOBPleSiQ7q2h7iL+sqNwdO+6eAFemhJuCbnN45s6EO
kiLaSbL61KP8Xd5tETgXK0yE+/5f1YpN4IsNEjBDovNuV3TH5sTzQkmhdm1qBEVP
yUI74rFhuZDFZ6S0DWM1G72CrG4wpOtFfFNFBBzvATHoA0CFRSZec0EMwF2weu87
Nq8KLw3v97peBP71JmwDyAILgzCEHab9/WPC9TSB6/JnzoTSEUolSw+pwbmcOahd
9mMWXy+aNsafyOXUger612wbcItvpBz/AIND23caVqtUuix96ycEEJmqHWd5vRN0
i6aHLxkjMmjodDrFeQDkiSBtSS6tO2kCitT4USo5MsZVMyZdvD8YWcvNrFHwgi7c
ZFXMEBfms0uz
=xaeq
-----END PGP SIGNATURE-----