-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.0 Source: mime-support Binary: mime-support Architecture: all Version: 3.58 Maintainer: Mime-Support Maintainers <[email protected]> Uploaders: Laszlo Boszormenyi (GCS) <[email protected]>, Charles Plessy <[email protected]> Standards-Version: 3.9.6 Vcs-Browser: http://anonscm.debian.org/gitweb/?p=collab-maint/mime-support.git Vcs-Git: git://anonscm.debian.org/collab-maint/mime-support.git Package-List: mime-support deb net standard arch=all Checksums-Sha1: 5e8c8dc952aee1adc589dbc1a2526f3eb83fd293 34995 mime-support_3.58.tar.gz Checksums-Sha256: 3d9ca5115e93edb3ada3fb120cde88ac3d866903e18a41ca124428d77dd1721e 34995 mime-support_3.58.tar.gz Files: 461430b0c9356ff3d7b0f0b61f9edf53 34995 mime-support_3.58.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUn6c7AAoJEMW9bI8ildUC1NAQAKZzsLgxmGPhSWhsN9kn1df2 73GU0trmTrm9Eny0WPrAfReZ+tqztnlxaNaIF26qVr2CTmDqEHXYau0UVAZiuC/N 8LUuq+h2GHWD0kusrQZB4ur4QnIcrSe3CucieMcEbIJ5TJfLqrEBUT66vkPgypmj EBfftNrj6rCG2bonRvsvF1UaDMM+BZegZgbw5X8W4d1l6Fu5VWQi/eorBi30aRBk TnPxIctU5BdrepDh9fusyLpz/bYdJxZlCs/w99iruCx27FBk+e+iXTErxH3cfm9u k8Pudni3dVTyU1fuy4QkoOKPnuaUS1wvLVMG7dWRZUC4TLG7az/0R4zd5wkleke4 day4bNi5f9lELtX8SZju+bONTs5anjGKpVxIAiZcCmqkt/+lgeSupExy95ceUfFC XvwCH/3tCZcfvPnkwMBfMUCDhoTQKIig12Y9dto9+2PcYB6SJfKNUZqPLTMUSl7w UFjujAYCbAIOoqH5zaBBkUcjO69SDtJ8FE0NP+ZK8LX30oQVng0LaFpPRVQnoRgK ASWsF2hOXXRIKzhLyXgRQ4DRA3i2dFFoHXJ7265XR176xWePmowjNQENibHLXBzT 7d2ZNV8+LRDo3IUm3bdn3zofHkYlzCiQEpu2uSAGmBH4fFvsCukFVc7CtRRd+5W6 oWQUQCnB2NcayHDdSugT =Kdhn -----END PGP SIGNATURE----- Changes: mime-support (3.58) unstable; urgency=high * CVE-2014-7209: run-mailcap shell command injection. Thanks to Timothy D. Morgan for the report. d156797 Escape file name also when not passed through %s. This avoids command injections using for instance semicolons. b585022 Resolve file name to an absolute path to avoid injection of command arguments with file names starting with dashes etc. Use File::Spec to avoid race conditions with temporary files. Thanks, Salvatore Bonaccorso for the patch. -- Charles Plessy <[email protected]> Sun, 28 Dec 2014 14:45:59 +0900