[ubuntu/raring-proposed] apt 0.9.7.7ubuntu3 (Accepted)

Michael Vogt michael.vogt at ubuntu.com
Thu Mar 14 13:30:19 UTC 2013


apt (0.9.7.7ubuntu3) raring; urgency=low

  * SECURITY UPDATE: InRelease verification bypass
    - CVE-2013-1051

  [ David Kalnischk ]
  * apt-pkg/deb/debmetaindex.cc,
    test/integration/test-bug-595691-empty-and-broken-archive-files,
    test/integration/test-releasefile-verification:
    - disable InRelease downloading until the verification issue is
      fixed, thanks to Ansgar Burchardt for finding the flaw

Date: Thu, 14 Mar 2013 14:25:56 +0100
Changed-By: Michael Vogt <michael.vogt at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/raring/+source/apt/0.9.7.7ubuntu3
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Thu, 14 Mar 2013 14:25:56 +0100
Source: apt
Binary: apt libapt-pkg4.12 libapt-inst1.5 apt-doc libapt-pkg-dev libapt-pkg-doc apt-utils apt-transport-https
Architecture: source
Version: 0.9.7.7ubuntu3
Distribution: raring
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Michael Vogt <michael.vogt at ubuntu.com>
Description: 
 apt        - commandline package manager
 apt-doc    - documentation for APT
 apt-transport-https - https download transport for APT
 apt-utils  - package managment related utility programs
 libapt-inst1.5 - deb package format runtime library
 libapt-pkg-dev - development files for APT's libapt-pkg and libapt-inst
 libapt-pkg-doc - documentation for APT development
 libapt-pkg4.12 - package managment runtime library
Changes: 
 apt (0.9.7.7ubuntu3) raring; urgency=low
 .
   * SECURITY UPDATE: InRelease verification bypass
     - CVE-2013-1051
 .
   [ David Kalnischk ]
   * apt-pkg/deb/debmetaindex.cc,
     test/integration/test-bug-595691-empty-and-broken-archive-files,
     test/integration/test-releasefile-verification:
     - disable InRelease downloading until the verification issue is
       fixed, thanks to Ansgar Burchardt for finding the flaw
Checksums-Sha1: 
 97c45b1b38eb1db7ff710f29218b644082d6c5fd 1777 apt_0.9.7.7ubuntu3.dsc
 649cff03901c03d3bce416ddc04ef12c38ac1015 3460092 apt_0.9.7.7ubuntu3.tar.gz
Checksums-Sha256: 
 8384689e34bb44ab10828e6378ad3eda0ddb2cc1734400f6acfbcbbbee338c24 1777 apt_0.9.7.7ubuntu3.dsc
 dd14b9c7332279bc96a6b393c9311d94720dc87116b8ac7406727a91798899a8 3460092 apt_0.9.7.7ubuntu3.tar.gz
Files: 
 f6b30b4852f1049c846164d0d35ba95e 1777 admin important apt_0.9.7.7ubuntu3.dsc
 93ff8f5fc38b5a0cd82cbee235e6a9e2 3460092 admin important apt_0.9.7.7ubuntu3.tar.gz
Original-Maintainer: APT Development Team <deity at lists.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAlFB0FgACgkQliSD4VZixzToqwCfVuntAjsEaNICJ/oFqez6dGmk
2fYAn0AexQ25jh4Yrnw2O50OXHSXf6Vb
=8n65
-----END PGP SIGNATURE-----


More information about the Raring-changes mailing list