Uploaded slrn 0.9.6.2-9 (alpha) to master
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.6
Date: Thu, 22 Jun 2000 18:26:33 -0700
Source: slrn
Binary: slrn slrnpull
Architecture: alpha
Version: 0.9.6.2-9
Distribution: unstable
Urgency: low
Maintainer: AlphaBuildd/John Goerzen <buildd@erwin.complete.org>
Description:
slrn - threaded news reader (fast for slow links)
slrnpull - pulls a small newsfeed from an NNTP server
Changes:
slrn (0.9.6.2-9) unstable; urgency=low
.
* Applied a patch from
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=12750 to fix
dozens of potential buffer overrun holes in slrn and slrnpull. These
include local environment variable overruns which Debian should not be
vulnerable to, since nothing in this package is installed setuid or
setgid (unlike Red Hat). It also includes theoretical remote exploits by
poisening newsgroup data. All theoretical, so I am not uploading it to
frozen, but I might as well apply the patch.
Files:
90ace6065c1d4cc0d4f93dd2c6b048b3 237184 news optional slrn_0.9.6.2-9_alpha.deb
d01782b242205a77a56b5159d8e21e71 75862 news optional slrnpull_0.9.6.2-9_alpha.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: Processed by Mailcrypt 3.5.5 and Gnu Privacy Guard <http://www.gnupg.org/>
iD8DBQE5VaNo3PeFtIodmh8RAoMKAKDKA/pel7yCsP2yFbNLxtzep/U6ngCgv3r6
zKd3EJ35+DdjK4vuQx6LC3g=
=Rlpu
-----END PGP SIGNATURE-----
Reply to: