-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 29 Aug 2021 19:03:02 +0200 Source: squashfs-tools Binary: squashfs-tools squashfs-tools-dbgsym Architecture: i386 Version: 1:4.3-12+deb10u1 Distribution: buster-security Urgency: high Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Thorsten Alteholz Description: squashfs-tools - Tool to create and append to squashfs filesystems Changes: squashfs-tools (1:4.3-12+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2021-40153 unsquashfs unvalidated filepaths allow writing outside of destination. Checksums-Sha1: ed7d8e145b600b39eee5aed5dcf916ef5ad9dc98 330484 squashfs-tools-dbgsym_4.3-12+deb10u1_i386.deb 6adeb0e40f182b71f53a376e1716a9791e3e30b9 5809 squashfs-tools_4.3-12+deb10u1_i386-buildd.buildinfo 8c48153e8bdc1a24f3068c932db5e1cc714796b5 138232 squashfs-tools_4.3-12+deb10u1_i386.deb Checksums-Sha256: 57014bd256adbda5e3f92e56df845ac201b4a0fa070b45ebe04354ec0269b19f 330484 squashfs-tools-dbgsym_4.3-12+deb10u1_i386.deb 4022791eec55ab381b7f2421448db44cb375270954aa71363f0a7d4dd7225c7e 5809 squashfs-tools_4.3-12+deb10u1_i386-buildd.buildinfo 354f9ee2cca9bd79cc9314f5e8ec0e6a3ea92bfde32b011ab8c14e56365d53cd 138232 squashfs-tools_4.3-12+deb10u1_i386.deb Files: 6f391d693edf3e63e82a17e7003f746a 330484 debug optional squashfs-tools-dbgsym_4.3-12+deb10u1_i386.deb 73b4a4166e73bf35e6c4e6db3b36b3b5 5809 kernel optional squashfs-tools_4.3-12+deb10u1_i386-buildd.buildinfo e1d826e74e663bb1be72b66f73da30fc 138232 kernel optional squashfs-tools_4.3-12+deb10u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEeShLnnjT5e2dm1q4H4Xht4aLclgFAmEzGQ0ACgkQH4Xht4aL cljGyg//ZJ/UVSPsPerbtBdIkM4xay9Ozd++zR3aLjAUOVFux12nG9OjPrl5cCQQ 7p2tXirzcHzDEuj8djNYZ7O0+i2uHHrYetUTswxw3FhK/JQ3p914z3Yrh35BYYiW tsVT6Bx2ThoaMsAoSSLDZHO4kD8DBiz+YFbbXMW41AbY4V20f+WUf733jS+1k85W +w/T1mYVk+6b2SU8bcQibBsu8FVfu/utVIa613JUXTxAVK5TsSl4N9gdog4EwRRq 8rx1ZUof1gfhYELK/FnbaftCcytD5CRNmos7XRc2L8eAIFLY3GXFi/sMytQq/7PN I/W8yxRFXSJtC0CBJeLQCSijMa4GJIelIV6Tfx7OiT5prQQAvflaaBDiEWiUn+Ag Eo5+2QqM+iwPVG4+b6Y7sfwUtk8pF/e+aWFBsZjMkWYFHFsQ7RayVaSl2rf7+tv9 NXb5+slEb//KV4hdhETC7Wx8Xm+52OlLoZmyV6QOGuMssNiernyKqeYQ/7lHJEM1 wFOItdsM/BLMH3ggIf2Q17LjgG2s/8k8Swbp9E5wkj0gECo5gHifyw29GawUcqWk RglyqfRcABECfaQyyIwPNvNe/YsTTLWBGN896+rH2IJaVnjyVTsl6T9E8FgZy7mz yxTopL2xwBXQQIGex3y6iS/7BZVda6/cpuSEFe5Tivs3BOdl9pY= =DUBM -----END PGP SIGNATURE-----