-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 29 Aug 2021 19:03:02 +0200 Source: squashfs-tools Binary: squashfs-tools squashfs-tools-dbgsym Architecture: armel Version: 1:4.4-2+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Thorsten Alteholz Description: squashfs-tools - Tool to create and append to squashfs filesystems Changes: squashfs-tools (1:4.4-2+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the LTS Team. * CVE-2021-40153 unsquashfs unvalidated filepaths allow writing outside of destination. Checksums-Sha1: b90b9717234c34aac7b16914c73a7fa2929731ee 383360 squashfs-tools-dbgsym_4.4-2+deb11u1_armel.deb 7b0f62b992894acc6a11e7803cf3403ae967588f 5829 squashfs-tools_4.4-2+deb11u1_armel-buildd.buildinfo 702817fd5da20530c7fb3737ce43cfc9cde92372 124888 squashfs-tools_4.4-2+deb11u1_armel.deb Checksums-Sha256: 4b6aeea0f2e692a1dddfd6fa807556a446bf65b5af14c3ef06bec9a4c7bec48a 383360 squashfs-tools-dbgsym_4.4-2+deb11u1_armel.deb 105bdf871f2e06f6bd75a54cf60fac5d80e67f0ad3794424e624de69d542bf66 5829 squashfs-tools_4.4-2+deb11u1_armel-buildd.buildinfo 4e14c9ad058a437ccb20232cc6e94732e2673b527c35ba85d21f74cd8633094e 124888 squashfs-tools_4.4-2+deb11u1_armel.deb Files: dcd022acb794709187f9731825a202bb 383360 debug optional squashfs-tools-dbgsym_4.4-2+deb11u1_armel.deb 6d08cc2d385db90dbf5b98c1d12d3967 5829 kernel optional squashfs-tools_4.4-2+deb11u1_armel-buildd.buildinfo f4b1837cf12a280eed9b674c1c275f6d 124888 kernel optional squashfs-tools_4.4-2+deb11u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiJiL30/whmFir9VAvQRvLIDzBdUFAmEzGboACgkQvQRvLIDz BdUbkg//ZqPM90u0RBzaD8evtxM1dnlfmSACCH3TsjgKB8z5XY0N1lXdjSGgng6n ccowJ34fuDGzHwUOT0xF5KiruCYyNEBrT8LkeEpv3Mw2HpJsFA1N1ojyeoVr4FZr nVcfasdZvfRzz/rA+/+8l92K8+zZrB/8ONLOb5Y8kRqB0xoglsnYwlRi+Fe1ue9D 3ozbxEXoSZqaei947SpY23V6ZLTAMLHjbVja5FkHXjE8oK3q7aRPZFlkCzC79276 tC4RY8kMq0MbEoHYcM3E8cAz0nxXgbgXDtIMrOdUBvQ2/3T2HFy6y0+vqcXrTzqf sY1y168zFHKLA+ydD+KscyhpLgGxbGyDSdQOEPtFuYgIuhuxITfRatverbci/Uul oJq6MzvXh9cEx9BLJHv/QPk9349N64no35y5syi3jo0MVfNkc3WnKj4iNQ+waQr5 54SkUwvTJXvv6mSbNbkX57FpFPrzBxwtFtoblfe3WeZlY32/7XnM7/s0qUkZQCtM O2p/I1QZQPncM3YXa2PuhP2GbONKcvpMtxgO7L2rivk1c/xxk+FnJABOlIFWU9+q hMMhoRR3xYkj9QLBl9ks2jVK/byoASRiTYJmv2M6C3eUuCATXlIa11yDeYgvYhPn mqQnhG87z65BnvHA30iMVK/4TJbQExKGtwppumdP4iWALBF71eE= =bc8l -----END PGP SIGNATURE-----