News for package dulwich

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 3.0 (quilt)
Source: dulwich
Binary: python-dulwich, python-dulwich-dbg
Architecture: any
Version: 0.8.5-2+deb7u2
Maintainer: Jelmer Vernooij <[email protected]>
Homepage: http://samba.org/~jelmer/dulwich
Standards-Version: 3.9.3
Vcs-Bzr: http://alioth.debian.org/~jelmer/bzr/dulwich/unstable
Build-Depends: python-all-dev (>= 2.6.6-3), python-all-dbg (>= 2.6.6-3), debhelper (>= 7.0.50~), python-unittest2, git (>= 1:1.7.0.4-2) | git-core, python-fastimport (>= 0.9.0~bzr293)
Package-List: 
 python-dulwich deb python optional
 python-dulwich-dbg deb debug extra
Checksums-Sha1: 
 b4e55125fd21908df02fa78efc3868a99636a2cb 203727 dulwich_0.8.5.orig.tar.gz
 6517746d273df7015c2a36791b8c06937e38c649 6447 dulwich_0.8.5-2+deb7u2.debian.tar.gz
Checksums-Sha256: 
 546d2840199500dc270da5bda456df68de4d1733f8b184bf425c5e560f988b6a 203727 dulwich_0.8.5.orig.tar.gz
 a438a3d06f90698dba5737b8589652ada3723065aafbf0b55132ac3015a939f3 6447 dulwich_0.8.5-2+deb7u2.debian.tar.gz
Files: 
 544724f9ac9fe6f9865526917ad284d9 203727 dulwich_0.8.5.orig.tar.gz
 920fc0d103d20f3f96232fa859603fb7 6447 dulwich_0.8.5-2+deb7u2.debian.tar.gz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJVFUtoAAoJEAVMuPMTQ89E48YP/i6LHad6XLiwL+MtbXdhhMyz
5BGV2kbyf7jFQXxOhM1bOf/ixtdYunmbiG1lgZKITQUPjIEJDQ/UZu/lGRqaEkEK
o5abH9YNOpmD69Fl4YvFsYFTFlyuOHk77vNQH89UlzdwwiDCTjFN7yS3Ok+ax64E
FoeNAzbT7S/+ixJ0mxMSVAZQ8+iOSuWmcsBWXJWmOhAdfDrS7cAZLfGtfhd+Pg1u
3f9ri5Olt4gxsgYS0AuK4MYGjzPdDxxo0ZhBqrt6wokAdXdEdPq9NGM/JzXAEjWk
l3ZYGFjqub/3/uRS2a0JWlQfin8AP0kBDfZUZ+IvVEDuHM0jwMKLHQh/pqdywBfH
Z08LSqvXbWzTG4J0qv7hcuMzDT9UvyQgm/5wiDUjbUre5e0LyqOi8p/brwU6qDQj
JGfFvWRcfz8TtRbU79LjaZ3CFr00n+ehEEFimSrxxkaoe/UZ2lUWJisaVU1+57rp
glai7Oy2AvJBGHn2qUkiEU3tVtGwsQEVcVBCGVI6DMupSIGjhZcWovyOAOAGtBS7
DhpqofdMRO7RIcHLIEyXJyfMneewzAKV9X0a8sOfBAfiXohezLV+k0RUnBbHuWqz
5SjVSqfg9Ef+B/eynbuPHBN1ZM6MdZCQbzQtkRNA7E8IRhWbYuvi1MiJftOvDb1v
wC3VdfPXotJw25eJNS2L
=HNFk
-----END PGP SIGNATURE-----

Changes:
dulwich (0.8.5-2+deb7u2) wheezy-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Add 03_CVE-2014-9706 patch.
    CVE-2014-9706: Don't allow writing to files under .git/ when checking
    out working trees. (Closes: #780989)

 -- Salvatore Bonaccorso <[email protected]>  Fri, 27 Mar 2015 13:18:17 +0100