Accepted slocate 2.7-1.1 (i386 source)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 21 Jan 2004 05:33:28 +0000
Source: slocate
Binary: slocate
Architecture: source i386
Version: 2.7-1.1
Distribution: testing-security
Urgency: high
Maintainer: Kevin Lindsay <klindsay@debian.org>
Changed-By: Kevin Lindsay <klindsay@debian.org>
Description:
slocate - a secure locate replacement
Changes:
slocate (2.7-1.1) testing-security; urgency=high
.
* 'slocate' sgid privileges are now dropped when searching databases that
are not apart of the 'slocate' group. This will prevent malicious user
supplied databases from elevating user access to the 'slocate' group.
See CAN-2003-0056. Reference debian bug #226103.
Files:
9b745e4a89f5b809a86050dc945a53a9 485 utils optional slocate_2.7-1.1.dsc
502602f4d1287a6e8c76e63685a75a75 92972 utils optional slocate_2.7-1.1.tar.gz
7b92f5c92d524b858cceb078cf85f269 26468 utils optional slocate_2.7-1.1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
iD8DBQFADhczUZpV8HRsUfQRAkScAJ0ctf/PTPGKB3ifGqyst334qFQjKwCdGoDo
Qv/oxWfDXc2ka1VHlcyBHr4=
=qYqa
-----END PGP SIGNATURE-----
Accepted:
slocate_2.7-1.1.dsc
to pool/main/s/slocate/slocate_2.7-1.1.dsc
slocate_2.7-1.1.tar.gz
to pool/main/s/slocate/slocate_2.7-1.1.tar.gz
slocate_2.7-1.1_i386.deb
to pool/main/s/slocate/slocate_2.7-1.1_i386.deb
Reply to: