Format: 1.8 Date: Fri, 08 Apr 2022 07:04:04 -0400 Source: gzip Binary: gzip Built-For-Profiles: noudeb Architecture: ppc64el Version: 1.10-4ubuntu1.1 Distribution: impish Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gzip - GNU compression utilities Changes: gzip (1.10-4ubuntu1.1) impish-security; urgency=medium . * SECURITY UPDATE: arbitrary file override with crafted file names - debian/patches/CVE-2022-1271-1.patch: avoid exploit via multi-newline file names in zgrep.in. - debian/patches/CVE-2022-1271-2.patch: add test in tests/Makefile.am, tests/zgrep-abuse. - debian/patches/CVE-2022-1271-3.patch: port to POSIX sed in zgrep.in. - debian/patches/CVE-2022-1271-4.patch: optimize out a grep in gzexe.in. - debian/patches/CVE-2022-1271-5.patch: use C locale more often in gzexe.in, sample/zfile, zdiff.in, zgrep.in, znew.in. - debian/patches/CVE-2022-1271-6.patch: fix "binary file matches" mislabeling in tests/Makefile.am, tests/zgrep-binary, zgrep.in. - debian/rules: fix permissions on new test scripts. - CVE-2022-1271 Checksums-Sha1: ad529b261d125b33d5d60e4b50ef42edaf9b94bf 129968 gzip-dbgsym_1.10-4ubuntu1.1_ppc64el.ddeb c71e2688c339bc0f7f990f1f02dcfe4ccf39b95a 6200 gzip_1.10-4ubuntu1.1_ppc64el.buildinfo 9b5a38d9f6a881af40d4372329882254f1cdbc2f 112454 gzip_1.10-4ubuntu1.1_ppc64el.deb Checksums-Sha256: 19166ee38cd2f0194e09454a40121eef4abcedbc0e1318bd02774327294e6987 129968 gzip-dbgsym_1.10-4ubuntu1.1_ppc64el.ddeb ee076a8bc45f4c3d10222372c276230b8061cd9643b03cd194841afd6c5088fc 6200 gzip_1.10-4ubuntu1.1_ppc64el.buildinfo 5f9557d5a8db3df33c16bd707f8ce061ab6df2cf0031ecf1dcd552650f9a473c 112454 gzip_1.10-4ubuntu1.1_ppc64el.deb Files: d667bc93a84496ec60d9a3b78c8c97dd 129968 debug optional gzip-dbgsym_1.10-4ubuntu1.1_ppc64el.ddeb 2cb686ccdf71b5e31e8a92fbea352ce1 6200 utils required gzip_1.10-4ubuntu1.1_ppc64el.buildinfo ebd745876953b0552d8aea750507cf7c 112454 utils required gzip_1.10-4ubuntu1.1_ppc64el.deb Original-Maintainer: Milan Kupcevic