-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sun, 11 Mar 2007 10:45:03 -0500 Source: ktorrent Binary: ktorrent Architecture: amd64_translations amd64 Version: 1.2-0ubuntu5.1 Distribution: dapper-security Urgency: low Maintainer: Ubuntu/amd64 Build Daemon Changed-By: Richard A. Johnson Description: ktorrent - BitTorrent client for KDE Changes: ktorrent (1.2-0ubuntu5.1) dapper-security; urgency=low . * SECURITY UPDATE: allows .. in file name which could cause the user to overwrite files (if ran as root, system files). DoS or heap corruption possible if idx is to small (negative) or to large. * Add 'debian/patches/kubuntu_02_security_fix.diff': backported upstream fix * References http://websvn.kde.org/?view=rev&revision=640661 CVE-2007-1384 CVE-2007-1385 Files: 1e15c2c9901fe1bd815d3ebebc33c841 799590 net optional ktorrent_1.2-0ubuntu5.1_amd64.deb 89deb4b5bb0f81e89cf3c24b7ab344d5 397833 raw-translations - ktorrent_1.2-0ubuntu5.1_amd64_translations.tar.gz Original-Maintainer: Joel Johnson -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFF9d2q0N0xjzyQZEIRAkvAAJ9BJpmtvb4uZrejDAsY7+tyMN+QSwCeMERX 8jBv5QYgTXO/3mK/auEb28A= =GFQG -----END PGP SIGNATURE-----