Thank you for your contribution to Debian.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 31 Oct 2025 12:47:09 +0300
Source: busybox
Architecture: source
Version: 1:1.37.0-7
Distribution: unstable
Urgency: medium
Maintainer: Debian Install System Team <debian-boot@lists.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Closes: 1055307 1119539
Changes:
busybox (1:1.37.0-7) unstable; urgency=medium
.
* patches/archival-disallow-path-traversals-CVE-2023-39810.patch
(Closes: #1055307, CVE-2023-39810)
* archival-disallow-path-traversals-CVE-2023-39810.patch:
use the correct "echo" when constructing the archive
* d/config/pkg/* CONFIG_FEATURE_PATH_TRAVERSAL_PROTECTION=y
* enable chattr and lsattr applets (Closes: #1119539)
* udeb: install all links in /usr/, do not touch /bin & /sbin
Checksums-Sha1:
9bcc3aa50d9ad73e611ec714f84d489b094a3f89 2377 busybox_1.37.0-7.dsc
9b6817999237674feee9aef35fff0dec261b2cb2 66864 busybox_1.37.0-7.debian.tar.xz
4e4c91bb74b879c0645bb54df879bf9c7a989804 5613 busybox_1.37.0-7_source.buildinfo
Checksums-Sha256:
2f3944fccc4e1dae361bebb29631f703a29751d2bca4f50e3e582876b1af8c8e 2377 busybox_1.37.0-7.dsc
f92b18875c8411c4bb5d024899fc0592b799e500fb0e4792a764352d380d2255 66864 busybox_1.37.0-7.debian.tar.xz
d94ac1e65cd72b5d6c899eb55533fcde79177ef7de145de2e519cf4bada93b38 5613 busybox_1.37.0-7_source.buildinfo
Files:
267448354ab2a2ae41ee15c01672ee2a 2377 utils optional busybox_1.37.0-7.dsc
dd7c740817de9e86a3e1b83a1c8a9d4d 66864 utils optional busybox_1.37.0-7.debian.tar.xz
40f11fae73b08fc24bbd595d31aebd0b 5613 utils optional busybox_1.37.0-7_source.buildinfo
-----BEGIN PGP SIGNATURE-----
wsG7BAEBCgBvBYJpBIWwCRCCqkokOx6UeEcUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmfBT4SEoErUBHc/OzQpxFSlo+AeiNdNXg6NlcB67FHZ
fBYhBGSqKrUx1WkDNmv++YKqSiQ7HpR4AADY1A/7BbLbXTxWPSGrKh7PrJ8Esbv8
GXTmadalyjABzquzHN0FZwl7pBriapx7GXiH0FHN3ciixlmMHR7DBUgOcBnc/nvf
EOZeUqXRu6wauM1iyF9Rv/xD8pnPHluFAu2zM9Rz9MSLGLpK31WbXTfw/gSOPjMk
da2Pp7+/wfImlkfkaJTwy2exBzjW0MdwKV++LNOCygf161jfCkii4hw1YlKj7zH1
bJnVLDHImGC6QT2D2hKXwT9k+n7SzRzGTxaKKeLKi1FANguma3KIgl3stbrxeH1p
cOvaKqKUxS0Y8ehcoH9a+R5qCyBHc4f4+PEMVhufpAzJ8K+eHum2goi7rC49dt/p
mPE6j6CVHYsibytcmVTP7Q7h3M15Id2wMxQuo30rYZ12CSPz2mymqubxSWD4UvBx
v9Li4MFAFwWyvMVOk/160c3xqiN7c2fTVzHscCOcYmb8HyMijBs3nE04cFlQX0sk
LBYcF3vL7P05Biy7HiAt50d3UhSroDCWQhP9P9KpPF9cUng4/JwFfECRRJXH+nwl
j0h4vuhhtJimhom6teKydNxP3TTQrTLy8boY+nPwv6NrKHxmGizUwXRwXg1Gx9be
SHoP8xzhzl2oYTzYn4mUVmgAtWjOGnbugcTlZN5wGeAqOe5gp3SU1qq/xWMc+qPF
5baoA54DjoB84Ts2cVI=
=7xeF
-----END PGP SIGNATURE-----
Attachment:
pgpxduVeWtspp.pgp
Description: PGP signature