Accepted libu2f-host 1.1.9-1 (source) into unstable
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 08 Mar 2019 11:59:52 +0100
Source: libu2f-host
Architecture: source
Version: 1.1.9-1
Distribution: unstable
Urgency: high
Maintainer: Debian Authentication Maintainers <team+auth@tracker.debian.org>
Changed-By: Nicolas Braud-Santoni <nicoo@debian.org>
Closes: 892779 921818 923874
Changes:
libu2f-host (1.1.9-1) unstable; urgency=high (security fix)
.
* New upstream version 1.1.9
+ Fix CVE-2019-9578 (Closes: #923874)
libu2f-host previously leaked uninitialized stack memory to the device
+ Provide udev rules that work for systemd and SysV init (Closes: #892779)
+ Add a new product id for the JaCarta U2F devices, in udev rules
.
* debian/libu2f-udev.postinst: Do not display udevadm commands
Closes: #921818
.
* debian/copyright: Update copyright lines
Checksums-Sha1:
9a9c4be2268e5992a2724060ff8b0bf1eeb474f3 2415 libu2f-host_1.1.9-1.dsc
422d55d8bb211b3f2d8e6797006e7758c2f223f9 470996 libu2f-host_1.1.9.orig.tar.xz
c2df1fe069d85947975354e24de1a4836869a6ef 49444 libu2f-host_1.1.9-1.debian.tar.xz
b7f69ff0cec7c1f97a5be94566bed754f356b743 12802 libu2f-host_1.1.9-1_amd64.buildinfo
Checksums-Sha256:
3c480ab73f170cd91b831482da48eab03208e64a4a08101149a96f316f2c1fa5 2415 libu2f-host_1.1.9-1.dsc
37daef025be55c71998c16d81d2b0bb3f9aa55b736e4e964da0774a6891bd0c2 470996 libu2f-host_1.1.9.orig.tar.xz
6a4b6279e83e81823b61cb4792eecf5cace1eed57b8a8d2b785607cf028f0982 49444 libu2f-host_1.1.9-1.debian.tar.xz
a51c0d9131ac4b089f83882e377997c8e96a6c32f8954e49d50739eb2c8cd789 12802 libu2f-host_1.1.9-1_amd64.buildinfo
Files:
69de17b0598cf33a6365e1aa4f4d490e 2415 utils optional libu2f-host_1.1.9-1.dsc
21fec8a219c051ca2e89b2ad4ac6ce0b 470996 utils optional libu2f-host_1.1.9.orig.tar.xz
f86e2e9c36e585a9071ff5f08ea0899e 49444 utils optional libu2f-host_1.1.9-1.debian.tar.xz
41357b4a17b8072dcfeb5ed15ea46501 12802 utils optional libu2f-host_1.1.9-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEU7EqA8ZVHYoLJhPE5vmO4pLV7MsFAlyCS9kACgkQ5vmO4pLV
7MvzGQ/9GtrdzSIhBPoMLoFS6SHv4OGCwQ3bKIHoEjS/7stEYQElI5M892J+dG0z
idvJAP8263KMXEeJ0BU+v/2KIzabdbNRy1+F6AQ2x1hxXeSRLef1aAdODHsnpH3A
kftFONBbc/FYW2RPWE/PGNJ9z4DubFNWMwlEflOpeYnh6vnkMy1PlA5WryRfn/uM
rmuqw8ZS1tjUpuwzBKARTX5/pDqZmwpMVy82apfCIhp3XYJ/xrIwtsBZYhC/dVJm
jjkKQnt+qF5A0GqDoycitBAqcyCaljy8CsSUd/d2pHKIO/1OTHtqu/ucohyTnakx
E4UR4sKHtM5HxtyeBSSa7iO7TVd8DsVqpMsFAaV6kQsvtQk8c5L5x+4gWQ3u/UUU
XeCn0EWYnnJCC/Ni85SPkksg+xQHXDt94wO/51jv+n1HCm7Dsyu9GicojmOlgHRS
vqqSbsSUA7u4r3GJMzL/G+S6QRTLBzY5+fiijGHanz5Vot/C+20TfobeUY+Vwv4l
9Ov/zdlk42FCBlVdilrMRIAQEn220aBV7knh3UKUyvKXeSPhOJFa+jdy55Bi+B9R
DJWAxaTAuiVFwOpDenahZcWjurpoI3dbFpyC3yJFZSm/UWzkmyFJETf98DPeom0V
9mzxbMFtOs6HXbivVvBunptJYZFvcVW2RKiX6kKx3J9wWtMHmUw=
=pW00
-----END PGP SIGNATURE-----